CVE-2026-64962
- EPSS -
- Veröffentlicht 20.08.2026 13:57:47
- Zuletzt bearbeitet 20.08.2026 16:17:32
ATutor is vulnerable to Cross-Site Request Forgery (CSRF) in profile update functionality. An attacker can craft a malicious website which, when visited by an authenticated victim, submits a forged request to the system. Due to the lack of proper CSR...
CVE-2026-64961
- EPSS -
- Veröffentlicht 20.08.2026 13:57:41
- Zuletzt bearbeitet 20.08.2026 16:17:32
ATutor is vulnerable to authentication bypass . Although a token validation check is present in the auto-login functionality, the values required for token validation remain uninitialized in certain code paths. An unauthenticated attacker who can det...
CVE-2026-64960
- EPSS -
- Veröffentlicht 20.08.2026 13:57:33
- Zuletzt bearbeitet 20.08.2026 16:17:31
ATutor Gameme module allows users to upload files of any type and extension without restriction. Due to improper handling of file uploads, files are stored in a web-accessible location before their content is validated. An authenticated attacker who ...
CVE-2026-6956
- EPSS 0.39%
- Veröffentlicht 11.05.2026 10:16:15
- Zuletzt bearbeitet 12.05.2026 14:15:25
ATutor is vulnerable to Reflected XSS in /install/install.php endpoint. An attacker can provide a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. Product is no longer actively supported. Ma...
CVE-2026-6909
- EPSS 0.39%
- Veröffentlicht 11.05.2026 10:16:15
- Zuletzt bearbeitet 12.05.2026 14:15:25
ATutor is vulnerable to Reflected XSS in /install/upgrade.php endpoint. An attacker can provide a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. Product is no longer actively supported. Ma...
CVE-2020-37147
- EPSS 0.28%
- Veröffentlicht 06.02.2026 23:14:08
- Zuletzt bearbeitet 15.04.2026 00:35:42
ATutor 2.2.4 contains a SQL injection vulnerability in the admin user deletion page that allows authenticated attackers to manipulate database queries through the 'id' parameter. Attackers can exploit the vulnerability by injecting malicious SQL code...
CVE-2023-27008
- EPSS 1.5%
- Veröffentlicht 28.03.2023 15:15:06
- Zuletzt bearbeitet 18.02.2025 21:15:15
A Cross-site scripting (XSS) vulnerability in the function encrypt_password() in login.tmpl.php in ATutor 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the token parameter.
CVE-2021-43498
- EPSS 1.62%
- Veröffentlicht 08.04.2022 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:29:19
An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden, and form_change HTTP POST parameters are set.
CVE-2020-23341
- EPSS 0.83%
- Veröffentlicht 17.08.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 05:13:45
A reflected cross site scripting (XSS) vulnerability in the /header.tmpl.php component of ATutor 2.2.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2015-1583
- EPSS 1.22%
- Veröffentlicht 02.03.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 02:25:42
Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account via a request to mods/_core/users/admins/create.php o...