Description
A stored-self XSS exists in ATutor through v2.2.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Real Name field to /mods/_core/users/admins/my_edit.php.
Remediation
References
Related Vulnerabilities
WordPress Plugin Convert Plus Security Bypass (3.4.4)
Oracle Database Server CVE-2011-0879 Vulnerability (CVE-2011-0879)
Jenkins Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-5323)
Oracle Database Server CVE-2008-2607 Vulnerability (CVE-2008-2607)
WordPress Plugin Simple visitor stat Cross-Site Scripting (1.0)