Description
A stored-self XSS exists in ATutor through v2.2.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Real Name field to /mods/_core/users/admins/my_edit.php.
Remediation
References
Related Vulnerabilities
WordPress Plugin WPS Hide Login Multiple Security Bypass Vulnerabilities (1.5.2.2)
WordPress Plugin FunCaptcha-Anti-Spam CAPTCHA Cross-Site Request Forgery (0.3.2)
WordPress Plugin SAML SP Single Sign On-SSO login Cross-Site Scripting (4.8.83)
WordPress Other Vulnerability (CVE-2006-1012)
WordPress Plugin Login with Azure (Azure SSO) Cross-Site Scripting (1.4.4)