Sploitus

CVE-2016-2539

5 known exploits for CVE-2016-2539

Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to hijack the authentication of users for requests that upload arbitrary files and execute arbitrary PHP code via vectors involving a crafted zip file.

Affected products
Atutor
Atutor
≤ 2.2.1
Fix
Available
CVSS 3.0
8.8 HIGH
EPSS
4.3% (90th percentile)
Weakness
CWE-352
NVD status
Modified
Published
2017-02-07
CVE-2016-2539 at NVD
Authoritative description, scoring and affected products

5 known exploits for CVE-2016-2539

Proof-of-concept code and exploit modules indexed by Sploitus