Executive brief
Xerte Online Tools, an open-source platform for creating interactive learning materials, contains a critical flaw in its installation component. An attacker can remotely trigger the setup process to take control of the application and connect it to a database they manage. This allows the attacker to steal sensitive data, disrupt educational services, or execute malicious code on the server.
Technical details
A vulnerability in Xerte Online Tools exists due to insufficient access controls on the /setup/ directory. An unauthenticated remote attacker can access the installation scripts to reconfigure the application, pointing it to an attacker-controlled database. By manipulating the configuration during this unauthorized reinstallation process, the attacker can achieve authentication bypass and remote code execution (RCE) on the underlying server. The issue stems from the setup folder not being automatically disabled or protected after the initial installation. Users are advised to upgrade to versions 3.14.6 or 3.15.5 and ensure the /setup/ folder is removed from the production environment.
Affected products
- Xerte Xerte Online Tools < 3.14.6, < 3.15.5
Timeline
- 2026-04-21: disclosed: Issue reported via GitHub
- 2026-07-09: advisory: NVD publication date