A critical vulnerability in ATutor 2.2.4 allows attackers to upload arbitrary files and perform directory traversal by submitting a specially crafted ZIP archive containing '..' pathnames to the language_import.php or index_admin.php components. This enables remote code execution on the affected system. The vulnerability is unpatched as ATutor is no longer maintained.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module (atutor_upload_traversal.rb) that exploits a combination of arbitrary file upload and directory traversal vulnerabilities in ATutor versions 2.2.4, 2.2.2, and 2.2.1 (CVE-2019-12169). The exploit requires valid admin credentials and targets both Linux and Windows installations (commonly on XAMPP for Windows). The module works by creating a ZIP archive with a malicious PHP payload, exploiting the directory traversal to place the PHP file in the web root, and then triggering its execution via an HTTP request. If the first upload vector ('Import New Language') fails, it attempts a second vector ('Patcher'). The payload is a customizable Meterpreter reverse shell or similar, providing full remote code execution. The module is weaponized, supporting multiple platforms and payloads, and is part of the Metasploit framework. The only file in the repository is the exploit module itself, written in Ruby.
This repository contains a Python exploit script (atutor-upload-rce.py) and a README for CVE-2019-12169, targeting ATutor 2.2.4. The exploit abuses a directory traversal vulnerability in the 'language_import' (and optionally 'patcher') component, allowing an attacker to upload a ZIP file containing a PHP webshell to the web root directory. The script logs in to the ATutor instance using provided credentials, uploads the malicious ZIP, and then interacts with the webshell via HTTP requests to execute arbitrary commands. The README provides context, usage instructions, and references. The exploit is operational, requiring valid credentials and network access to the target. Key endpoints include the login page, the vulnerable language import endpoint, and the webshell URL. The payload is a PHP webshell, and the exploit works on both Windows and Linux installations of ATutor.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.