CVE-2026-6956
- EPSS 0.39%
- Veröffentlicht 11.05.2026 10:16:15
- Zuletzt bearbeitet 12.05.2026 14:15:25
ATutor is vulnerable to Reflected XSS in /install/install.php endpoint. An attacker can provide a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. Product is no longer actively supported. Ma...
CVE-2026-6909
- EPSS 0.39%
- Veröffentlicht 11.05.2026 10:16:15
- Zuletzt bearbeitet 12.05.2026 14:15:25
ATutor is vulnerable to Reflected XSS in /install/upgrade.php endpoint. An attacker can provide a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. Product is no longer actively supported. Ma...
CVE-2020-37147
- EPSS 0.28%
- Veröffentlicht 06.02.2026 23:14:08
- Zuletzt bearbeitet 15.04.2026 00:35:42
ATutor 2.2.4 contains a SQL injection vulnerability in the admin user deletion page that allows authenticated attackers to manipulate database queries through the 'id' parameter. Attackers can exploit the vulnerability by injecting malicious SQL code...
CVE-2023-27008
- EPSS 1.5%
- Veröffentlicht 28.03.2023 15:15:06
- Zuletzt bearbeitet 18.02.2025 21:15:15
A Cross-site scripting (XSS) vulnerability in the function encrypt_password() in login.tmpl.php in ATutor 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the token parameter.
CVE-2021-43498
- EPSS 1.59%
- Veröffentlicht 08.04.2022 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:29:19
An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden, and form_change HTTP POST parameters are set.
CVE-2020-23341
- EPSS 0.83%
- Veröffentlicht 17.08.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 05:13:45
A reflected cross site scripting (XSS) vulnerability in the /header.tmpl.php component of ATutor 2.2.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2015-1583
- EPSS 1.22%
- Veröffentlicht 02.03.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 02:25:42
Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account via a request to mods/_core/users/admins/create.php o...
CVE-2014-9753
- EPSS 2.91%
- Veröffentlicht 11.02.2020 18:15:16
- Zuletzt bearbeitet 21.11.2024 02:21:35
confirm.php in ATutor 2.2 and earlier allows remote attackers to bypass authentication and gain access as an existing user via the auto_login parameter.
CVE-2019-16114
- EPSS 4.78%
- Veröffentlicht 09.09.2019 13:15:11
- Zuletzt bearbeitet 21.11.2024 04:30:04
In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which allows him to gain access to the application. Next, he can change the directory that the application uploads files to, wh...
CVE-2019-12169
- EPSS 73.32%
- Veröffentlicht 03.06.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:22:21
ATutor 2.2.4 allows Arbitrary File Upload and Directory Traversal, resulting in remote code execution via a ".." pathname in a ZIP archive to the mods/_core/languages/language_import.php (aka Import New Language) or mods/_standard/patcher/index_admin...