CVE-2015-1583: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account via a request to mods/core/users/admins/create.php or (2) create a user account via a request to mods/core/users/createuser.php.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1583?
CVE-2015-1583 is considered a medium-severity vulnerability due to its potential impact on administrator accounts via CSRF attacks.
How do I fix CVE-2015-1583?
To resolve CVE-2015-1583, apply security patches provided by ATutor or upgrade to a version that addresses these CSRF vulnerabilities.
Who is affected by CVE-2015-1583?
CVE-2015-1583 affects users of ATutor version 2.2, particularly those with administrative access.
What types of attacks are possible with CVE-2015-1583?
CVE-2015-1583 allows remote attackers to perform cross-site request forgery attacks, potentially hijacking admin authentication.
What platform does CVE-2015-1583 target?
CVE-2015-1583 specifically targets the ATutor learning management system version 2.2.