Atutor
39 known vulnerabilities
Top Products
A Cross-site scripting (XSS) vulnerability in the function encrypt_password() in login.tmpl.php in ATutor 2.2.1 allows r
An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden,
A reflected cross site scripting (XSS) vulnerability in the /header.tmpl.php component of ATutor 2.2.4 allows attackers
An issue was discovered in AContent through 1.4. It allows the user to run commands on the server with a low-privileged
Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentica
confirm.php in ATutor 2.2 and earlier allows remote attackers to bypass authentication and gain access as an existing us
In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted databas
ATutor 2.2.4 allows Arbitrary File Upload and Directory Traversal, resulting in remote code execution via a ".." pathnam
ATutor through 2.2.4 is vulnerable to arbitrary file uploads via the mods/_core/backups/upload.php (aka backup) componen
An issue was discovered in ATutor through 2.2.4. It allows the user to run commands on the server with the teacher user
A stored-self XSS exists in ATutor through v2.2.4, allowing an attacker to execute HTML or JavaScript code in a vulnerab
Multiple cross-site scripting (XSS) vulnerabilities in ATutor LMS version 2.2.
Cross-Site Scripting (XSS) was discovered in ATutor before 2.2.3. The vulnerability exists due to insufficient filtratio
Cross-site scripting (XSS) vulnerability in popuphelp.php in ATutor 2.2 and earlier allows remote attackers to inject ar
Directory Traversal exists in ATutor before 2.2.2 via the icon parameter to /mods/_core/courses/users/create_course.php.
ATutor version 2.2.1 and earlier are vulnerable to a SQL injection in the Assignment Dropbox, BasicLTI, Blog Post, Blog,
ATutor versions 2.2.1 and earlier are vulnerable to an incorrect access control check vulnerability in the Social Applic
ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbi
Multiple Cross-Site Scripting (XSS) issues were discovered in ATutor 2.2.2. The vulnerabilities exist due to insufficien
Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to
Frequently Asked Questions
How many CVEs affect Atutor?
Atutor has 39 CVE records in our database, including 6 critical and 11 high severity vulnerabilities.
What are the most severe Atutor vulnerabilities?
Atutor has 6 critical severity (CVSS 9.0+) and 11 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Atutor vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Atutor products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Atutor Vulnerabilities
CyberStrike scans your infrastructure for Atutor vulnerabilities and provides real-time remediation guidance.
Get Started