peter bassill · operator
$ cve CVE-2019-11446 JSON

CVE-2019-11446 EXPLOIT

8.8
HIGH · CVSS 3.0 · EPSS 7.8% (pctl 94)

Patch early

A public exploit exists.

Description

An issue was discovered in ATutor through 2.2.4. It allows the user to run commands on the server with the teacher user privilege. The Upload Files section in the File Manager field contains an arbitrary file upload vulnerability via upload.php. The $IllegalExtensions value only lists lowercase (and thus .phP is a bypass), and omits .shtml and .phtml.

Scoring

CVSS8.8 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS7.8% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-434
On CISA KEVno
Public exploityes
Published2019-04-22
Last modified2026-06-17

Affected (1)

VendorProduct
atutoratutor

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD