Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Wed, 12 Aug 2015 12:30:56 +0530
From: sreepriya <sreepriya1111@...il.com>
To: oss-security@...ts.openwall.com, cve-assign@...re.org
Subject: CVE Request: ATutor LMS Version 2.2 with stored XSS and file upload issue

Hello,

I would like to request for a CVE  for the following issues in the latest
version of ATutor <http://www.atutor.ca/> learning management system.

There are a few Stored XSS and file upload vulnerabilities in the software.
*Issue*: https://github.com/atutor/ATutor/issues/103

*Stored/Persistent XSS:*
In course management, multiple user inputs are not sanitized.
Course name and banner are vulnerable to Stored XSS.

*File Upload:*
An instructor can upload a malicious script (I tried Javascript that gets
executed in browser if opened after download). Not just the file content,
the file name is also vulnerable. This leaves the students (lower
privilege) as well as the administrators (higher privilege) vulnerable to
the attack.

*Date of reporting*: 11th August, 2015
*Exploit Author* : Sreepriya Chalakkal
*Vendor Homepage*: http://www.atutor.ca/
*Software Link*: http://www.atutor.ca/atutor/download.php
*Version *: 2.2
*Tested on Linux* : Ubuntu, Kali
*Issue has been reported to the vendor: *
https://github.com/atutor/ATutor/issues/103

Please let me know if it is possible to get a CVE identifier assigned for
the above issue.

​Thanks and ​
Regards,
--
Sreepriya C
priyachalakkal.wordpress.com <http://www.priyachalakkal.wordpress.com>

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.