CVE-2019-16114 is a critical vulnerability affecting ATutor 2.2.4 that allows an unauthenticated attacker to gain full control over the application. The flaw stems from insufficient restrictions in the installation process, enabling an attacker to manipulate database settings and the file upload directory. This permits remote code execution, leading to a complete compromise of the system. With a CVSS score of 9.8 (CRITICAL), the vulnerability is easily exploitable over the network with no user interaction, resulting in high impact to confidentiality, integrity, and availability. Despite its severity, there is currently no public exploit intelligence, nor is it listed on the CISA KEV catalog, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.2.4CPE matchmatch criteria | cpe:2.3:a:atutor:atutor:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.