vendor:
ATutor Learning Management System
by:
Saravana Kumar
7.5
CVSS
HIGH
Cross-Site Request Forgery
CWE
Product Name: ATutor Learning Management System
Affected Version From: 2.2.2002
Affected Version To: 2.2.2002
Patch Exists: YES
Related CWE:
CPE: a:atutor:atutor:2.2.2
Platforms Tested: Kali Linux 2.0, Windows 7
2016
ATutor_2.2.2 Learning Management System Cross-Site Request Forgery (Add New Course)
This vulnerability allows an attacker to perform unauthorized actions on behalf of the victim by tricking them into clicking on a malicious link or visiting a malicious website. In this case, the vulnerability allows an attacker to add a new course to the ATutor Learning Management System without proper authentication.
Mitigation:
The vendor has fixed the vulnerability and released a patch. Users are advised to update to the latest version of ATutor (2.2.2) to mitigate the risk.