Executive brief
ATutor, an open-source learning management system used for online courses, contains a security flaw in its installation and upgrade component. An attacker can trick a user into clicking a malicious link, allowing the attacker to execute unauthorized scripts in the user's web browser. This could lead to the theft of session information or unauthorized actions performed on behalf of the user.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in ATutor version 2.2.4 within the /install/upgrade.php script. The application fails to properly neutralize user-supplied input before including it in the generated web page. An unauthenticated remote attacker can exploit this by persuading a victim to visit a specially crafted URL. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session. The product is no longer supported, and no patch is available.
Affected products
- ATutor ATutor 2.2.4
Timeline
- 2026-05-11: advisory: Advisory published by CERT Polska and NVD