Description
A stored-self XSS exists in ATutor through v2.2.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Real Name field to /mods/_core/users/admins/my_edit.php.
Remediation
References
Related Vulnerabilities
Nexus Repository Manager Incorrect Default Permissions Vulnerability (CVE-2019-9630)
WordPress Plugin Modern Events Calendar Lite Multiple Vulnerabilities (5.16.5)
ownCloud Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2013-0301)
MySQL CVE-2015-4862 Vulnerability (CVE-2015-4862)
WordPress Plugin Multisite Post Duplicator Cross-Site Request Forgery (0.9.5.1)