Release date:
Updated on:
Affected Systems:
ATutor AContent 1.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 56100
Cve id: CVE-2012-5168
AContent is an e-learning content creation tool and library that supports the import, export, and production of IMS content packages.
A security vulnerability exists in versions earlier than ATutor AContent 1.2-1. By directly requesting user/index_inline_editor_submit.php or course_category/index_inline_editor_submit.php, remote attackers can modify any user password or directory name.
<* Source: High-Tech Bridge Security Research Lab
Link: http://secunia.com/advisories/51034
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
ATutor
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://atutor.ca/