6.5
CVSSv2

CVE-2015-7712

Published: 16/11/2015 Updated: 09/10/2018
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Multiple eval injection vulnerabilities in mods/_standard/gradebook/edit_marks.php in ATutor 2.2 and previous versions allow remote authenticated users with the AT_PRIV_GRADEBOOK privilege to execute arbitrary PHP code via the (1) asc or (2) desc parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

atutor atutor

Exploits

ATutor versions 22 and below suffer from a remote php code injection vulnerability ...