CVE-2020-37147
7.0
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: disclosure@vulncheck.com (Secondary)
Description
ATutor 2.2.4 contains a SQL injection vulnerability in the admin user deletion page that allows authenticated attackers to manipulate database queries through the 'id' parameter. Attackers can exploit the vulnerability by injecting malicious SQL code into the 'id' parameter of the admin_delete.php script to potentially extract or modify database information.
References (3)
Source: disclosure@vulncheck.com
Source: disclosure@vulncheck.com
Source: disclosure@vulncheck.com
Timeline (7)
2/7/20267 changes
New CVE Received - Reference
12:15 AM
- -
+ https://www.vulncheck.com/advisories/atutor-id-sql-injection
New CVE Received - Reference
12:15 AM
- -
+ https://www.exploit-db.com/exploits/48117
New CVE Received - Reference
12:15 AM
- -
+ https://atutor.github.io/
New CVE Received - CWE
12:15 AM
- -
+ CWE-89
New CVE Received - CVSS V3.1
12:15 AM
- -
+ AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
New CVE Received - CVSS V4.0
12:15 AM
- -
+ AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
New CVE Received - Description
12:15 AM
- -
+ ATutor 2.2.4 contains a SQL injection vulnerability in the admin user deletion page that allows authenticated attackers to manipulate database queries through the 'id' parameter. Attackers can exploit the vulnerability by injecting malicious SQL code into the 'id' parameter of the admin_delete.php script to potentially extract or modify database information.