Description
Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to hijack the authentication of users for requests that upload arbitrary files and execute arbitrary PHP code via vectors involving a crafted zip file.
Remediation
References
Related Vulnerabilities
WordPress Plugin Youtube Channel Gallery Cross-Site Scripting (2.4)
WordPress Plugin WordPress Button Plugin MaxButtons Security Bypass (1.19.0)
phpMyAdmin Improper Authentication Vulnerability (CVE-2018-12613)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-9735)