Executive brief
ATutor, an open-source learning management system used for online courses, contains a security flaw in its installation component. An attacker can trick a user into clicking a malicious link, allowing the attacker to run unauthorized scripts in the user's web browser. This could lead to the theft of login sessions or sensitive information within the application.
Technical details
A Reflected Cross-Site Scripting (XSS) vulnerability exists in ATutor version 2.2.4 within the '/install/install.php' script. The vulnerability stems from improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by enticing a victim to visit a specially crafted URL. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session. The product is no longer supported, and no official patch is available.
Affected products
- ATutor ATutor 2.2.4 (other versions may be affected)
Timeline
- 2026-05-11: advisory: Advisory published by CERT Polska
- 2026-05-11: disclosed: CVE-2026-6956 published to NVD