Description
Multiple Cross-Site Scripting (XSS) issues were discovered in ATutor 2.2.2. The vulnerabilities exist due to insufficient filtration of user-supplied data passed to several pages (lang_code in themes/*/admin/system_preferences/language_edit.tmpl.php). An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
Remediation
References
Related Vulnerabilities
TYPO3 CVE-2024-25119 Vulnerability (CVE-2024-25119)
WordPress Plugin YOP Poll Cross-Site Scripting (6.1.1)
TYPO3 Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-7073)
WordPress Plugin WP Fastest Cache Arbitrary File Deletion (0.8.9.0)
WordPress Plugin WP Download Codes Cross-Site Scripting (2.5.1)