CVE-2019-7172: XSS
Published Jan 29, 2019
·Updated
A stored-self XSS exists in ATutor through v2.2.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Real Name field to /mods/core/users/admins/myedit.php.
Affected Software
1 affected component
ATutor ATutor<=2.2.4
Event History
Jan 29, 2019
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-7172?
The severity of CVE-2019-7172 is considered to be high due to its potential for stored cross-site scripting (XSS).
2
How do I fix CVE-2019-7172?
To fix CVE-2019-7172, update ATutor to version 2.2.5 or higher to eliminate the vulnerability in the Real Name field.
3
What type of vulnerability is CVE-2019-7172?
CVE-2019-7172 is a stored cross-site scripting (XSS) vulnerability affecting ATutor.
4
Which versions of ATutor are affected by CVE-2019-7172?
CVE-2019-7172 affects ATutor versions up to and including 2.2.4.
5
Can CVE-2019-7172 be exploited remotely?
Yes, CVE-2019-7172 can be exploited remotely by executing malicious JavaScript code through the vulnerable Real Name field.