Atutor

Atutor

44 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 20.08.2026 13:58:45
  • Zuletzt bearbeitet 20.08.2026 16:17:38

ATutor is vulnerable to Reflected XSS via popup parameter in preview.php. An authenticated attacker can inject a double quote into the popup parameter, break out of the attribute value, and append a new event handler such as onload. The related previ...

  • EPSS -
  • Veröffentlicht 20.08.2026 13:58:39
  • Zuletzt bearbeitet 20.08.2026 16:17:37

ATutor is vulnerable to Reflected XSS in restore functionality. An attacker can provide a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. Product is no longer actively supported and the vuln...

  • EPSS -
  • Veröffentlicht 20.08.2026 13:58:33
  • Zuletzt bearbeitet 20.08.2026 16:17:37

ATutor is vulnerable to Stored Cross Site Scripting in registration functionality.  An attacker can register a new account and enter a JavaScript payload in the phone field during registration. When any authenticated user visits the attacker's public...

  • EPSS -
  • Veröffentlicht 20.08.2026 13:58:27
  • Zuletzt bearbeitet 20.08.2026 16:17:36

ATutor is vulnerable to Insecure Direct Object Reference (IDOR) attack in profile picture related endpoints. Any authenticated user, including a student, can supply another user's member_id in a POST request to the profile album endpoint and permanen...

  • EPSS -
  • Veröffentlicht 20.08.2026 13:58:22
  • Zuletzt bearbeitet 20.08.2026 16:17:36

ATutor is vulnerable to Server-Side request forgery in import functionalities. An authenticated administrator can make the server request arbitrary internal HTTP endpoints, cloud metadata services, or local files via file:// if the PHP environment pe...

  • EPSS -
  • Veröffentlicht 20.08.2026 13:58:17
  • Zuletzt bearbeitet 20.08.2026 16:17:35

A path traversal vulnerability in ATutor's error log viewer allows an attacker with administrative privileges to access arbitrary files outside the intended logs directory. This can lead to unauthorized access to sensitive files and other resources a...

  • EPSS -
  • Veröffentlicht 20.08.2026 13:58:11
  • Zuletzt bearbeitet 20.08.2026 16:17:35

ATutor is vulnerable to a Path Traversal vulnerability in ZIP extraction functionality. An attacker with instructor privileges can upload and extract a specially crafted ZIP archive, causing files to be written outside the intended extraction directo...

  • EPSS -
  • Veröffentlicht 20.08.2026 13:58:06
  • Zuletzt bearbeitet 20.08.2026 16:17:34

ATutor is vulnerable to Missing Authorization Check on Test and Question Import endpoints.  A low-privileged authenticated user (e.g. a student) enrolled in a course can bypass authorization checks by sending requests directly to the backend import e...

  • EPSS -
  • Veröffentlicht 20.08.2026 13:58:00
  • Zuletzt bearbeitet 20.08.2026 16:17:33

ATutor generates predictable email confirmation tokens due to the use of insufficiently random values in the account confirmation functionality. Due to the use of predictable values related to user registration, an attacker who knows or can predict t...

  • EPSS -
  • Veröffentlicht 20.08.2026 13:57:53
  • Zuletzt bearbeitet 20.08.2026 16:17:33

A path traversal vulnerability in ATutor allows an authenticated user to access files from other course directories when the AT_FORCE_GET_FILE configuration option is enabled. This can lead to unauthorized access to files and disclosure of informatio...