Junglewise Threat Intelligence

CVE-2026-64962: ATutor CSRF in profile update

CVE-2026-64962 · Severity: info · Published 2026-08-20

Technologies: ATutor. Vendors: ATutor.

Executive brief

ATutor is an open-source learning management system used by organizations to deliver online courses and educational content. The profile update functionality lacks proper cross-site request forgery (CSRF) protections, allowing an attacker to trick authenticated users into modifying their own profile information by visiting a malicious website. This could enable account compromise, unauthorized profile changes, and potential lateral movement within the system.

Technical details

This vulnerability is a cross-site request forgery (CSRF) flaw in ATutor's profile update functionality. The root cause is the absence of proper CSRF token validation on state-changing requests. An attacker can craft a malicious webpage containing hidden form submissions or JavaScript that, when viewed by an authenticated ATutor user, causes the victim's browser to submit forged requests to update their profile information. Since the vulnerable code does not verify a unique, unpredictable token on the request, the update succeeds without the user's knowledge. The attack requires a victim to be actively logged into ATutor and to visit attacker-controlled content. No patch is available, as the product is no longer actively maintained.

Affected products

  • ATutor ATutor 2.2.4

Timeline

  • 2026-08-20: disclosed

References

Related threats