VYPR

Atutor

by Atutor

Source repositories

CVEs (58)

  • CVE-2019-7172MedJan 29, 2019
    risk 0.40cvss 6.1epss 0.01

    A stored-self XSS exists in ATutor through v2.2.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Real Name field to /mods/_core/users/admins/my_edit.php.

  • CVE-2015-7711MedAug 31, 2017
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in popuphelp.php in ATutor 2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the h parameter.

  • CVE-2017-6483MedMar 5, 2017
    risk 0.40cvss 6.1epss 0.01

    Multiple Cross-Site Scripting (XSS) issues were discovered in ATutor 2.2.2. The vulnerabilities exist due to insufficient filtration of user-supplied data passed to several pages (lang_code in themes/*/admin/system_preferences/language_edit.tmpl.php). An attacker could execute…

  • CVE-2015-6521MedOct 10, 2017
    risk 0.35cvss 5.4epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in ATutor LMS version 2.2.

  • CVE-2017-14981MedOct 3, 2017
    risk 0.35cvss 5.4epss 0.01

    Cross-Site Scripting (XSS) was discovered in ATutor before 2.2.3. The vulnerability exists due to insufficient filtration of data (url in /mods/_standard/rss_feeds/edit_feed.php). An attacker could inject arbitrary HTML and script code into a browser in the context of the…

  • CVE-2026-64969MedAug 20, 2026
    risk 0.34cvss —epss 0.00

    ATutor is vulnerable to Insecure Direct Object Reference (IDOR) attack in profile picture related endpoints. Any authenticated user, including a student, can supply another user's member_id in a POST request to the profile album endpoint and permanently delete that user's…

  • CVE-2026-64965MedAug 20, 2026
    risk 0.34cvss —epss 0.00

    ATutor is vulnerable to Missing Authorization Check on Test and Question Import endpoints.  A low-privileged authenticated user (e.g. a student) enrolled in a course can bypass authorization checks by sending requests directly to the backend import endpoints, allowing the…

  • CVE-2026-64970MedAug 20, 2026
    risk 0.33cvss —epss 0.00

    ATutor is vulnerable to Stored Cross Site Scripting in registration functionality.  An attacker can register a new account and enter a JavaScript payload in the phone field during registration. When any authenticated user visits the attacker's public profile, the profile…

  • CVE-2026-64968MedAug 20, 2026
    risk 0.33cvss —epss 0.00

    ATutor is vulnerable to Server-Side request forgery in import functionalities. An authenticated administrator can make the server request arbitrary internal HTTP endpoints, cloud metadata services, or local files via file:// if the PHP environment permits URL wrappers. …

  • CVE-2026-64962MedAug 20, 2026
    risk 0.33cvss —epss 0.00

    ATutor is vulnerable to Cross-Site Request Forgery (CSRF) in profile update functionality. An attacker can craft a malicious website which, when visited by an authenticated victim, submits a forged request to the system. Due to the lack of proper CSRF token implementation, the…

  • CVE-2026-6956MedMay 11, 2026
    risk 0.33cvss —epss 0.01

    ATutor is vulnerable to Reflected XSS in /install/install.php endpoint. An attacker can provide a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. Product is no longer actively supported. Maintainers of this project…

  • CVE-2026-6909MedMay 11, 2026
    risk 0.33cvss —epss 0.01

    ATutor is vulnerable to Reflected XSS in /install/upgrade.php endpoint. An attacker can provide a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. Product is no longer actively supported. Maintainers of this project…

  • CVE-2026-64972MedAug 20, 2026
    risk 0.31cvss —epss 0.00

    ATutor is vulnerable to Reflected XSS via popup parameter in preview.php. An authenticated attacker can inject a double quote into the popup parameter, break out of the attribute value, and append a new event handler such as onload. The related preview_top.php file sanitises…

  • CVE-2026-64971MedAug 20, 2026
    risk 0.31cvss —epss 0.01

    ATutor is vulnerable to Reflected XSS in restore functionality. An attacker can provide a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. Product is no longer actively supported and the vulnerabilities have not been…

  • CVE-2026-64963LowAug 20, 2026
    risk 0.15cvss —epss 0.01

    A path traversal vulnerability in ATutor allows an authenticated user to access files from other course directories when the AT_FORCE_GET_FILE configuration option is enabled. This can lead to unauthorized access to files and disclosure of information about the filesystem…

  • CVE-2005-3404Nov 1, 2005
    risk 0.04cvss —epss 0.10

    Multiple PHP file inclusion vulnerabilities in ATutor 1.4.1 through 1.5.1-pl1 allow remote attackers to include arbitrary files via the section parameter followed by a null byte (%00) in (1) body_header.inc.php and (2) print.php.

  • CVE-2005-3405Nov 1, 2005
    risk 0.04cvss —epss 0.08

    ATutor 1.4.1 through 1.5.1-pl1 allows remote attackers to execute arbitrary PHP functions via a direct request to forum.inc.php with a modified addslashes parameter with either the (1) asc or (2) desc parameters set, possibly due to an eval injection vulnerability.

  • CVE-2014-2091Mar 2, 2014
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in mods/_standard/forums/admin/forum_add.php in ATutor 2.1.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the title parameter in an add_forum action. NOTE: the original disclosure also reported…

  • CVE-2012-6528Jan 31, 2013
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in ATutor before 2.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) themes/default/tile_search/index.tmpl.php, (2) login.php, (3) search.php, (4) password_reminder.php, (5)…

  • CVE-2010-0971Mar 16, 2010
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.6.4 allow remote authenticated users, with Instructor privileges, to inject arbitrary web script or HTML via the (1) Question and (2) Choice fields in tools/polls/add.php, the (3) Type and (4) Title fields in…