logo

Vulnerabilities in ATutor software

ID: a0a2b670-19d6-59dc-9c1b-f511f83068d9

STIX ID: report--a0a2b670-19d6-59dc-9c1b-f511f83068d9

Feed Name: CERT Polska

Threat Score
75/100

Date Published: 2026-08-20

Date Updated: 2026-08-20

Author: CERT Polska

...
...

CERT Polska coordinated disclosure describes 13 distinct CVEs affecting ATutor version 2.2.4, including high-impact issues such as remote code execution via unrestricted file upload and ZIP extraction, authentication bypass allowing token-based login without a password, server-side request forgery, multiple path traversal issues, CSRF, IDOR, and both stored and reflected XSS. The report notes the product is no longer actively supported, only version 2.2.4 was tested and confirmed vulnerable, and the issues have not been fixed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.