CVE-2012-5454: Medium severity atutor acontent vulnerability
user/indexinlineeditorsubmit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated users to modify arbitrary user passwords via a crafted request. NOTE: this might be due to an incomplete fix for CVE-2012-5168.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5454?
CVE-2012-5454 is considered a medium severity vulnerability due to the risk of user password modification by authenticated users.
How do I fix CVE-2012-5454?
To fix CVE-2012-5454, ensure that access controls are properly implemented in the user/index_inline_editor_submit.php file.
Who is affected by CVE-2012-5454?
CVE-2012-5454 specifically affects users of ATutor AContent version 1.2-1.
What are the implications of CVE-2012-5454?
The implications of CVE-2012-5454 include the potential for unauthorized password changes, which could compromise user accounts.
Is CVE-2012-5454 related to another vulnerability?
Yes, CVE-2012-5454 might be related to an incomplete fix for CVE-2012-5168.