Description
An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden, and form_change HTTP POST parameters are set.
Remediation
References
Related Vulnerabilities
SharePoint CVE-2021-1716 Vulnerability (CVE-2021-1716)
Python Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-1015)
TYPO3 Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2013-4321)
WordPress Plugin AMP Toolbox Cross-Site Scripting (1.9.4)
WordPress Plugin Virtual Robots.txt Cross-Site Scripting (1.9)