Executive brief
ATutor is an open-source learning management system used to host and manage online courses. An administrative user can exploit a path traversal vulnerability in the error log viewer to read arbitrary files accessible to the web server, potentially exposing sensitive configuration files, database credentials, or other confidential data stored on the server.
Technical details
This is a path traversal (CWE-22) vulnerability in ATutor's error log viewer component. An attacker with administrative privileges can manipulate file path inputs to escape the intended logs directory and access arbitrary files on the system. The vulnerability requires administrative access, limiting the attack surface to trusted insiders or attackers who have already compromised an admin account. Successful exploitation allows reading sensitive files accessible by the web server process. ATutor is no longer actively supported, and no patches are available; only version 2.2.4 has been confirmed vulnerable.
Affected products
- ATutor ATutor 2.2.4 (confirmed); other versions untested but possibly vulnerable
Timeline
- 2026-08-20: disclosed