CVE-2017-1000004: SQL Injection
ATutor version 2.2.1 and earlier are vulnerable to a SQL injection in the Assignment Dropbox, BasicLTI, Blog Post, Blog, Group Course Email, Course Alumni, Course Enrolment, Group Membership, Course unenrolment, Course Enrolment List Search, Glossary, Social Group Member Search, Social Friend Search, Social Group Search, File Comment, Gradebook Test Title, User Group Membership, Inbox/Sent Items, Sent Messages, Links, Photo Album, Poll, Social Application, Social Profile, Test, Content Menu, Auto-Login, and Gradebook components resulting in information disclosure, database modification, or potential code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1000004?
CVE-2017-1000004 is considered high severity due to its potential for SQL injection attacks that could compromise the database.
How do I fix CVE-2017-1000004?
To fix CVE-2017-1000004, upgrade to ATutor version 2.2.2 or later where the vulnerability has been patched.
What systems are affected by CVE-2017-1000004?
CVE-2017-1000004 affects ATutor versions 2.2.1 and earlier.
What types of attacks are possible with CVE-2017-1000004?
CVE-2017-1000004 allows attackers to execute arbitrary SQL queries, potentially leading to data leaks or unauthorized access.
Is CVE-2017-1000004 easy to exploit?
Yes, CVE-2017-1000004 is relatively easy to exploit if proper security measures and input sanitization are not implemented.