LOW
Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.6.4 allow remote authenticated users, with Instructor privileges, to inject arbitrary web script or HTML via the (1) Question and (2) Choice fields in tools/polls/add.php, the (3) Type and (4) Title fields in tools/groups/create_manual.php, and the (5) Title field in assignments/add_assignment.php
Published Mar 16, 2010
2.1
LOWCVSS 2.0
EPSS 1.65%
Description
Affected products
Remediation
Metrics
References (8)
Change history (0)
No recorded changes yet.