Description
confirm.php in ATutor 2.2 and earlier allows remote attackers to bypass authentication and gain access as an existing user via the auto_login parameter.
Remediation
References
Related Vulnerabilities
WordPress Authentication Bypass Using an Alternate Path or Channel Vulnerability (CVE-2020-4050)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-3553)
WordPress Plugin InstaWP Connect-1-click WP Staging & Migration Security Bypass (0.1.0.24)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-4360)