CVE-2019-12170

HIGH

ATutor <= 2.2.4 - Authenticated Arbitrary File Upload via Backup ZIP Archive

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2019-12170. PoCs published by fuzzlove, fuzzlove-group.

AI-analyzed exploit summary This repository provides a detailed technical writeup for CVE-2019-12170, an arbitrary file upload vulnerability in ATutor 2.2.4 that leads to remote command execution. It includes step-by-step exploitation instructions, affected paths, and references to external PoC files.

Description

ATutor through 2.2.4 is vulnerable to arbitrary file uploads via the mods/_core/backups/upload.php (aka backup) component. This may result in remote command execution. An attacker can use the instructor account to fully compromise the system using a crafted backup ZIP archive. This will allow for PHP files to be written to the web root, and for code to execute on the remote server.

Exploits (2)

nomisec WRITEUP 2 stars
by fuzzlove · poc
https://github.com/fuzzlove/ATutor-Instructor-Backup-Arbitrary-File

This repository provides a detailed technical writeup for CVE-2019-12170, an arbitrary file upload vulnerability in ATutor 2.2.4 that leads to remote command execution. It includes step-by-step exploitation instructions, affected paths, and references to external PoC files.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: ATutor < 2.2.4
Auth required
Prerequisites: Instructor account credentials · Access to the backup/upload functionality
devstral-2 · analyzed Feb 18, 2026 Full analysis →
gitlab WRITEUP
by fuzzlove-group · poc
https://gitlab.com/fuzzlove-group/ATutor-Instructor-Backup-Arbitrary-File

This repository provides a detailed technical writeup for CVE-2019-12170, an arbitrary file upload vulnerability in ATutor 2.2.4 and prior versions. It explains the exploit steps, including authentication, navigation to the backup upload function, and execution of a crafted ZIP file to achieve remote command execution.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: ATutor < 2.2.4
Auth required
Prerequisites: instructor account credentials · access to the backup/upload functionality
devstral-2 · analyzed Feb 23, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/fuzzlove/ATutor-Instructor-Backup-Arbitrary-File
Exploit, Third Party Advisory, URL Repurposed x_refsource_misc
http://incidentsecurity.com/atutor-2-2-4-backup-remote-command-execution/

Scores

CVSS v3 8.8
EPSS 0.0875
EPSS Percentile 94.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
atutor/atutor < 2.2.4
Published May 17, 2019
Tracked Since Feb 18, 2026