CVE-2015-7712: Medium severity atutor achecker vulnerability
Multiple eval injection vulnerabilities in mods/standard/gradebook/editmarks.php in ATutor 2.2 and earlier allow remote authenticated users with the ATPRIVGRADEBOOK privilege to execute arbitrary PHP code via the (1) asc or (2) desc parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7712?
CVE-2015-7712 is classified as a critical vulnerability due to the potential for remote code execution.
How do I fix CVE-2015-7712?
To mitigate CVE-2015-7712, upgrade to a version of ATutor later than 2.2 to eliminate the eval injection vulnerabilities.
Who is affected by CVE-2015-7712?
CVE-2015-7712 affects remote authenticated users who have the AT_PRIV_GRADEBOOK privilege in ATutor 2.2 and earlier.
What are the consequences of exploiting CVE-2015-7712?
Exploiting CVE-2015-7712 allows attackers to execute arbitrary PHP code, potentially leading to full system compromise.
What components are vulnerable in CVE-2015-7712?
The vulnerable components in CVE-2015-7712 include mods/_standard/gradebook/edit_marks.php in ATutor.