|
Message-ID: <CANzWz4HNTYJgq=6-6yH-gwMugY=ck=CwxxtysXsbv9xAKP5X9Q@mail.gmail.com> Date: Wed, 12 Aug 2015 12:30:56 +0530 From: sreepriya <sreepriya1111@...il.com> To: oss-security@...ts.openwall.com, cve-assign@...re.org Subject: CVE Request: ATutor LMS Version 2.2 with stored XSS and file upload issue Hello, I would like to request for a CVE for the following issues in the latest version of ATutor <http://www.atutor.ca/> learning management system. There are a few Stored XSS and file upload vulnerabilities in the software. *Issue*: https://github.com/atutor/ATutor/issues/103 *Stored/Persistent XSS:* In course management, multiple user inputs are not sanitized. Course name and banner are vulnerable to Stored XSS. *File Upload:* An instructor can upload a malicious script (I tried Javascript that gets executed in browser if opened after download). Not just the file content, the file name is also vulnerable. This leaves the students (lower privilege) as well as the administrators (higher privilege) vulnerable to the attack. *Date of reporting*: 11th August, 2015 *Exploit Author* : Sreepriya Chalakkal *Vendor Homepage*: http://www.atutor.ca/ *Software Link*: http://www.atutor.ca/atutor/download.php *Version *: 2.2 *Tested on Linux* : Ubuntu, Kali *Issue has been reported to the vendor: * https://github.com/atutor/ATutor/issues/103 Please let me know if it is possible to get a CVE identifier assigned for the above issue. Thanks and Regards, -- Sreepriya C priyachalakkal.wordpress.com <http://www.priyachalakkal.wordpress.com>
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.