ATutor "tool_file" Local File Inclusion Vulnerability
Description
A vulnerability has been discovered in ATutor, which can be exploited by malicious users to disclose certain sensitive information.
Input passed via the "tool_file" parameter to mods/_core/tool_manager/index.php (while "h" is set to "1") is not properly verified before being used to include files. This can be exploited to include arbitrary files from local resources via directory traversal sequences.
The vulnerability is confirmed in version 2.1. Prior versions may also be affected.