Security Advisory

CVE-2017-1000002

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2017-07-13 20:00:00
Last updated 2024-08-05 21:45:25
Assigner mitre
State PUBLISHED

Description

ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting in code execution. ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal vulnerability in the Course Icon component resulting in information disclosure.