Description
PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authenticated administrators to execute arbitrary PHP code via a URL in the type parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin ProfileGrid-User Profiles, Groups and Communities Cross-Site Scripting (2.6.6)
WordPress Plugin wp-tmkm-amazon Cross-Site Scripting (1.5b)
WordPress Plugin Wordfence Security-Firewall & Malware Scan Cross-Site Scripting (5.1.2)
WebLogic Deserialization of Untrusted Data Vulnerability (CVE-2020-11620)
Oracle Database Server CVE-2023-21949 Vulnerability (CVE-2023-21949)