Improper access control in ATutor - CVE-2019-16114
Published: September 9, 2019
ATutor
Detailed vulnerability description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in install/include/header.php. A remote non-authenticated attacker can bypass implemented security restrictions and gain unauthorized access to the application, upload files to the server and compromise the entire system.