ATutor AContent prior to 1.2-1 allows remote malicious users to modify arbitrary user passwords or category names via a direct request to (1) user/index_inline_editor_submit.php or (2) course_category/index_inline_editor_submit.php.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
atutor acontent |