CVE-2019-11446 EXPLOIT
8.8
HIGH · CVSS 3.0 · EPSS 7.8% (pctl 94)
Patch early
A public exploit exists.
Description
An issue was discovered in ATutor through 2.2.4. It allows the user to run commands on the server with the teacher user privilege. The Upload Files section in the File Manager field contains an arbitrary file upload vulnerability via upload.php. The $IllegalExtensions value only lists lowercase (and thus .phP is a bypass), and omits .shtml and .phtml.
Scoring
| CVSS | 8.8 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 7.8% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-434 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2019-04-22 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| atutor | atutor |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | ATutor < 2.2.4 - 'file_manager' Remote Code Execution (Metasploit) | 2019-04-12 |
References
→ the Explorer · watch your stack · NVD