CVE-2020-37147

ATutor 2.2.4 contains a SQL injection vulnerability in the admin user deletion page that allows authenticated attackers to manipulate database queries through the 'id' parameter. Attackers can exploit the vulnerability by injecting malicious SQL code into the 'id' parameter of the admin_delete.php script to potentially extract or modify database information.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) ATutor 2.2.4 contiene una vulnerabilidad de inyección SQL en la página de eliminación de usuarios administradores que permite a atacantes autenticados manipular consultas de base de datos a través del parámetro 'id'. Los atacantes pueden explotar la vulnerabilidad inyectando código SQL malicioso en el parámetro 'id' del script admin_delete.php para potencialmente extraer o modificar información de la base de datos.

07 Feb 2026, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-07 00:15

Updated : 2026-06-17 03:17


NVD link : CVE-2020-37147

Mitre link : CVE-2020-37147

CVE.ORG link : CVE-2020-37147


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')