PoC Index

CVE-2019-11446

HIGH 8.8EPSS 7.8%

An issue was discovered in ATutor through 2.2.4. It allows the user to run commands on the server with the teacher user privilege. The Upload Files section in the File Manager field contains an arbitrary file upload vulnerability via upload.php. The $IllegalExtensions value only lists lowercase (and thus .phP is a bypass), and omits .shtml and .phtml.

CVSS v3.0
8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
7.80% chance of exploitation in the next 30 days, 94th percentile
Published
2019-04-22
Updated
2024-08-04

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related