Security Advisory
CVE-2020-37147
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
ATutor 2.2.4 contains a SQL injection vulnerability in the admin user deletion page that allows authenticated attackers to manipulate database queries through the id parameter. Attackers can exploit the vulnerability by injecting malicious SQL code into the id parameter of the admin_delete.php script to potentially extract or modify database information.