Description
ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting in code execution. ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal vulnerability in the Course Icon component resulting in information disclosure.
Remediation
References
Related Vulnerabilities
WordPress Plugin All-in-One WP Migration Multiple Cross-Site Request Forgery Vulnerabilities (7.1)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-0798)
MyBB Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-9403)
WordPress Plugin Grid Gallery-Photo Image Grid Gallery Cross-Site Scripting (1.2.4)