Unrated severityNVD Advisory· Published Oct 22, 2012· Updated Jun 16, 2026
CVE-2012-5454
CVE-2012-5454
Description
user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated users to modify arbitrary user passwords via a crafted request. NOTE: this might be due to an incomplete fix for CVE-2012-5168.
Affected products
2Patches
Vulnerability mechanics
References
4- www.htbridge.com/advisory/HTB23117nvdExploit
- secunia.com/advisories/51034nvdVendor Advisory
- osvdb.org/86428nvd
- www.securityfocus.com/bid/56237nvd
News mentions
0No linked articles in our index yet.