CVE-2012-5168: High severity atutor acontent vulnerability
ATutor AContent before 1.2-1 allows remote attackers to modify arbitrary user passwords or category names via a direct request to (1) user/indexinlineeditorsubmit.php or (2) coursecategory/indexinlineeditorsubmit.php.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5168?
CVE-2012-5168 is considered a medium severity vulnerability due to its impact on user data and authentication.
How do I fix CVE-2012-5168?
To fix CVE-2012-5168, update ATutor AContent to the latest version that is not vulnerable, specifically beyond version 1.2.
What types of attacks are possible with CVE-2012-5168?
CVE-2012-5168 allows remote attackers to modify user passwords and category names, leading to unauthorized access or data manipulation.
Who is affected by CVE-2012-5168?
Any installation of ATutor AContent version 1.2 or earlier is affected by CVE-2012-5168.
What components of ATutor AContent are vulnerable in CVE-2012-5168?
The vulnerable components in CVE-2012-5168 are the user/index_inline_editor_submit.php and course_category/index_inline_editor_submit.php scripts.