Executive brief
ATutor is an open-source learning management system used to host online courses. A vulnerability in the user registration and profile display allows attackers to inject malicious JavaScript code via the phone field, which executes in the browsers of other users viewing the attacker's public profile. This enables theft of session cookies and account compromise for any authenticated user who views the attacker's profile.
Technical details
This is a stored cross-site scripting (XSS) vulnerability in ATutor's registration and profile functionality. The vulnerability exists because user input from the phone field during registration is not properly output-encoded when the profile template displays it to other users. An unauthenticated attacker can register a new account and inject JavaScript code in the phone field; when any authenticated user visits the attacker's public profile page, the unencoded phone value is echoed into the HTML response, causing the browser to execute the injected payload. This allows the attacker to steal session cookies and hijack user accounts. The product is no longer actively maintained, and no patch is available.
Affected products
- ATutor ATutor 2.2.4 (and possibly other versions)
Timeline
- 2026-08-20: disclosed
- 2026-08-20: advisory