Vulnerability record · CVE-2019-12169 · published 3 June 2019
CVE-2019-12169: ATutor language import and patcher path traversal enables file upload RCE
Atutor · Atutor
ATutor 2.2.4 fails to properly validate ZIP archive pathnames in the Import New Language and Patcher components, allowing directory traversal via ".." sequences. An attacker can use this to write files outside the intended directory and achieve remote code execution. The flaw is remotely reachable and public exploit code exists.
Description
ATutor 2.2.4 allows Arbitrary File Upload and Directory Traversal, resulting in remote code execution via a ".." pathname in a ZIP archive to the mods/_core/languages/language_import.php (aka Import New Language) or mods/_standard/patcher/index_admin.php (aka Patcher) component.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution with public exploit code and very high EPSS, but exploitation requires user interaction and the product is a legacy LMS.
What it is
ATutor 2.2.4 fails to properly validate ZIP archive pathnames in the Import New Language and Patcher components, allowing directory traversal via ".." sequences. An attacker can use this to write files outside the intended directory and achieve remote code execution. The flaw is remotely reachable and public exploit code exists.
Impact
An attacker can upload and place arbitrary files on the server, leading to remote code execution with the privileges of the web server. This gives full compromise of the ATutor host and any data it holds.
Attack surface
Reached over the network through the language import or patcher administrative functionality; the CVSS vector indicates no privileges are required but user interaction is needed, meaning a victim must be induced to trigger the crafted archive.
Exploitation
Public exploit code is referenced in multiple advisories and Packet Storm entries, and EPSS is high at roughly 0.73 (99th percentile), though the CVE is not listed in CISA KEV.
What to do
- Upgrade ATutor to a version later than 2.2.4 that fixes the path traversal in language import and patcher.
- If upgrade is not possible, disable or restrict access to the Import New Language and Patcher administrative components.
- Validate and sanitize ZIP entry names on upload, rejecting any containing ".." or absolute paths.
- Restrict web server write permissions so uploaded content cannot execute in web-accessible directories.
- Require strong authentication and limit administrative functions to trusted networks.
Detection
- Monitor web logs for POST requests to mods/_core/languages/language_import.php and mods/_standard/patcher/index_admin.php.
- Alert on ZIP uploads containing entries with ".." or absolute path components.
- Watch for newly written files in web-accessible directories outside expected upload paths.
- Detect unexpected child processes spawned by the web server user.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-12169 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-12169), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.