Short Name |
HTTP:ATUTOR-CSRF |
---|---|
Severity |
Minor |
Recommended |
No |
Category |
HTTP |
Keywords |
ATutor LCMS 2.2 Cross Site Request Forgery |
Release Date |
2019/07/24 |
Update Number |
3191 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts to exploit a known vulnerability against ATutor LCMS 2.2. Attackers can execute Cross Site Request Forgery attacks.
Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account via a request to mods/_core/users/admins/create.php or (2) create a user account via a request to mods/_core/users/create_user.php.