CVE-2012-5167: SQL Injection
Multiple SQL injection vulnerabilities in ATutor AContent before 1.2-1 allow remote attackers to execute arbitrary SQL commands via the (1) field parameter to coursecategory/indexinlineeditorsubmit.php or (2) user/indexinlineeditorsubmit.php; or (3) id parameter to user/userpassword.php.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5167?
CVE-2012-5167 is considered a critical vulnerability due to its potential for remote SQL injection attacks.
How do I fix CVE-2012-5167?
To fix CVE-2012-5167, upgrade your ATutor AContent to version 1.2-1 or later where the vulnerabilities have been patched.
What are the affected components in CVE-2012-5167?
CVE-2012-5167 affects multiple scripts including course_category/index_inline_editor_submit.php and user/index_inline_editor_submit.php.
Can CVE-2012-5167 lead to data compromise?
Yes, CVE-2012-5167 can allow attackers to execute arbitrary SQL commands which may lead to data compromise.
Who is at risk from CVE-2012-5167?
Any users running affected versions of ATutor AContent prior to 1.2-1 are at risk from CVE-2012-5167.