Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated users to modify arbitrary user passwords via a crafted request. NOTE: this might be due to an incomplete fix for CVE-2012-5168.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ATutor AContent ‘user/index_inline_editor_submit.php’脚本安全漏洞
Vulnerability Description
ATutor是ATutor团队开发的一套开源的基于Web的学习内容管理系统(LCMS)。该系统包括教学内容管理、论坛、聊天室等模块。 ATutor AContent 1.2-1版本中的user/index_inline_editor_submit.php脚本中存在漏洞,该漏洞源于没有正确限制访问。远程认证攻击者可利用该漏洞通过特制的请求修改任意用户密码。
CVSS Information
N/A
Vulnerability Type
N/A