Description
ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting in code execution. ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal vulnerability in the Course Icon component resulting in information disclosure.
Remediation
References
Related Vulnerabilities
MySQL CVE-2023-22059 Vulnerability (CVE-2023-22059)
WordPress Plugin Social Media Widget by Acurax Cross-Site Scripting (2.2)
MediaWiki Improper Encoding or Escaping of Output Vulnerability (CVE-2020-35475)
PostgreSQL Insufficiently Protected Credentials Vulnerability (CVE-2021-23222)
SharePoint Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-1023)