CVE-2014-9753 describes a critical authentication bypass vulnerability in ATutor versions 2.2 and earlier, specifically within the confirm.php script. This flaw allows remote attackers to gain unauthorized access as an existing user by manipulating the auto_login parameter. With a CVSS score of 9.8 (CRITICAL), it presents a high-impact threat due to its network-based attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. While no public exploit intelligence (Metasploit, Nuclei, ExploitDB) is currently available, and there's minimal community discussion or media coverage, its high FAUCET Risk Score of 81/100 indicates a significant inherent risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.2CPE matchmatch criteria | cpe:2.3:a:atutor:atutor:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.