Executive brief
ATutor is a learning management system (LMS) used by educational institutions to deliver online courses and assessments. A vulnerability allows low-privileged students enrolled in a course to import tests and questions without proper authorization, potentially corrupting course content or inserting unauthorized assessment material that could affect course integrity and student grades.
Technical details
The vulnerability is a missing authorization check (CWE-862) in the backend import endpoints for tests and questions. Low-privileged authenticated users (e.g., students) can bypass authorization controls by sending direct requests to these endpoints, allowing unauthorized import operations within a course. The attack requires an authenticated account and course enrollment but does not require instructor/administrator privileges. ATutor 2.2.4 is confirmed vulnerable; other versions are unknown. The product is no longer actively maintained and no patch is available.
Affected products
- ATutor ATutor 2.2.4
Timeline
- 2026-08-20: disclosed