CVE-2020-37147

HIGH

ATutor 2.2.4 - SQL Injection

Title source: llm
STIX 2.1

Description

ATutor 2.2.4 contains a SQL injection vulnerability in the admin user deletion page that allows authenticated attackers to manipulate database queries through the 'id' parameter. Attackers can exploit the vulnerability by injecting malicious SQL code into the 'id' parameter of the admin_delete.php script to potentially extract or modify database information.

Exploits (1)

exploitdb WRITEUP
by Andrey Stoykov · textwebappsphp
https://www.exploit-db.com/exploits/48117

Scores

CVSS v3 7.1
EPSS 0.0001
EPSS Percentile 1.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
Atutor/ATutor 2.2.4
Published Feb 07, 2026
Tracked Since Feb 18, 2026