668
VMScore

CVE-2017-1000004

Published: 17/07/2017 Updated: 04/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

ATutor version 2.2.1 and previous versions are vulnerable to a SQL injection in the Assignment Dropbox, BasicLTI, Blog Post, Blog, Group Course Email, Course Alumni, Course Enrolment, Group Membership, Course unenrolment, Course Enrolment List Search, Glossary, Social Group Member Search, Social Friend Search, Social Group Search, File Comment, Gradebook Test Title, User Group Membership, Inbox/Sent Items, Sent Messages, Links, Photo Album, Poll, Social Application, Social Profile, Test, Content Menu, Auto-Login, and Gradebook components resulting in information disclosure, database modification, or potential code execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

atutor atutor

Github Repositories

ATutor SQL Injection Vulnerability SQL Injection In order to examine and study the CVE-2017-1000004 vulnerability, a brief explanation of a SQL Injection Attack is required Any web application that takes user input is vulnerable SQL injection or SQLi is an injection attack where the attacker can execute malicious SQL statements in the user input that controls the database ser