← Vulnerability feed

Vulnerability record · CVE-2019-12169 · published 3 June 2019

CVE-2019-12169: ATutor language import and patcher path traversal enables file upload RCE

Atutor · Atutor

ATutor 2.2.4 fails to properly validate ZIP archive pathnames in the Import New Language and Patcher components, allowing directory traversal via ".." sequences. An attacker can use this to write files outside the intended directory and achieve remote code execution. The flaw is remotely reachable and public exploit code exists.

8.8 CVSS 3.1 High EPSS 72% · top 0.6% CWE-22 · Path traversal
8.8CVSS 3.1 base score, v2 6.8
72%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 8 tagged exploit
17 Jun 2026Last modified by NVD

Description

ATutor 2.2.4 allows Arbitrary File Upload and Directory Traversal, resulting in remote code execution via a ".." pathname in a ZIP archive to the mods/_core/languages/language_import.php (aka Import New Language) or mods/_standard/patcher/index_admin.php (aka Patcher) component.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityRemote code execution with public exploit code and very high EPSS, but exploitation requires user interaction and the product is a legacy LMS.

What it is

ATutor 2.2.4 fails to properly validate ZIP archive pathnames in the Import New Language and Patcher components, allowing directory traversal via ".." sequences. An attacker can use this to write files outside the intended directory and achieve remote code execution. The flaw is remotely reachable and public exploit code exists.

Impact

An attacker can upload and place arbitrary files on the server, leading to remote code execution with the privileges of the web server. This gives full compromise of the ATutor host and any data it holds.

Attack surface

Reached over the network through the language import or patcher administrative functionality; the CVSS vector indicates no privileges are required but user interaction is needed, meaning a victim must be induced to trigger the crafted archive.

Exploitation

Public exploit code is referenced in multiple advisories and Packet Storm entries, and EPSS is high at roughly 0.73 (99th percentile), though the CVE is not listed in CISA KEV.

What to do

  • Upgrade ATutor to a version later than 2.2.4 that fixes the path traversal in language import and patcher.
  • If upgrade is not possible, disable or restrict access to the Import New Language and Patcher administrative components.
  • Validate and sanitize ZIP entry names on upload, rejecting any containing ".." or absolute paths.
  • Restrict web server write permissions so uploaded content cannot execute in web-accessible directories.
  • Require strong authentication and limit administrative functions to trusted networks.

Detection

  • Monitor web logs for POST requests to mods/_core/languages/language_import.php and mods/_standard/patcher/index_admin.php.
  • Alert on ZIP uploads containing entries with ".." or absolute path components.
  • Watch for newly written files in web-accessible directories outside expected upload paths.
  • Detect unexpected child processes spawned by the web server user.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-12169 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-9753Atutor improper authentication vulnerabilityconfirm.php in ATutor 2.2 and earlier allows remote attackers to bypass authentication and gain access as an existing user via the auto_login paramet…EPSS 2.9%9.8CVE-2019-16114Atutor incorrect authorization vulnerabilityIn ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which allows him to gain a…EPSS 4.8%9.8CVE-2017-1000003Atutor improper privilege management vulnerabilityATutor versions 2.2.1 and earlier are vulnerable to an incorrect access control check vulnerability in the Social Application component resulting in …EPSS 2.3%9.8CVE-2017-1000004Atutor sql injection vulnerabilityATutor version 2.2.1 and earlier are vulnerable to a SQL injection in the Assignment Dropbox, BasicLTI, Blog Post, Blog, Group Course Email, Course A…EPSS 4.7%9.8CVE-2017-1000002Atutor path traversal vulnerabilityATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting in code e…EPSS 31%9.8CVE-2016-2555ATutor searchFriends SQL injection in mysql_connect.inc.phpATutor 2.2.1 passes the searchFriends function input from friends.inc.php into SQL through include/lib/mysql_connect.inc.php without proper sanitizat…EPSS 80%analysed8.8CVE-2015-1583Atutor cross-site request forgery vulnerabilityMultiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentication of administrators for re…EPSS 1.2%8.8CVE-2019-12170Atutor unrestricted file upload vulnerabilityATutor through 2.2.4 is vulnerable to arbitrary file uploads via the mods/_core/backups/upload.php (aka backup) component. This may result in remote …EPSS 8.6%

Source: NIST National Vulnerability Database (record CVE-2019-12169), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.