Unrated severityNVD Advisory· Published Oct 22, 2012· Updated Apr 29, 2026
CVE-2012-5454
CVE-2012-5454
Description
user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated users to modify arbitrary user passwords via a crafted request. NOTE: this might be due to an incomplete fix for CVE-2012-5168.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.htbridge.com/advisory/HTB23117nvdExploit
- secunia.com/advisories/51034nvdVendor Advisory
- osvdb.org/86428nvd
- www.securityfocus.com/bid/56237nvd
News mentions
0No linked articles in our index yet.