HTTP: ATutor LCMS 2.2 Cross Site Request Forgery

This signature detects attempts to exploit a known vulnerability against ATutor LCMS 2.2. Attackers can execute Cross Site Request Forgery attacks.

Extended Description

Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account via a request to mods/_core/users/admins/create.php or (2) create a user account via a request to mods/_core/users/create_user.php.

Affected Products

Atutor atutor

References

CVE: CVE-2015-1583

Short Name
HTTP:ATUTOR-CSRF
Severity
Minor
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
2.2 ATutor CVE-2015-1583 Cross Forgery LCMS Request Site
Release Date
07/24/2019
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
False Positive
Occasionally
Vendors

Atutor

CVSS Score

6.8

Found a potential security threat?