ATutor是Atutor组织开源的一款在线学习管理系统。 ATutor 2.2.4版本存在跨站脚本漏洞,该漏洞源于preview.php文件中popup参数处理不当,可能导致经过身份验证的攻击者注入双引号并添加事件处理程序,造成反射型跨站脚本攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-64960 | 8.7 HIGH | Remote Code Execution via Unrestricted File Upload in ATutor |
| CVE-2026-64966 | 8.7 HIGH | Path Traversal leading to Remote Code Execution in ATutor |
| CVE-2026-64967 | 6.9 MEDIUM | Path Traversal in ATutor |
| CVE-2026-64964 | 6.3 MEDIUM | Generation of Predictable Email Confirmation Token in ATutor |
| CVE-2026-64961 | 6.3 MEDIUM | Authentication Bypass in ATutor |
| CVE-2026-64965 | 5.3 MEDIUM | Missing Authorization Check in ATutor |
| CVE-2026-64969 | 5.3 MEDIUM | Insecure Direct Object Reference in ATutor |
| CVE-2026-64968 | 5.1 MEDIUM | Server-Side Request Forgery in ATutor |
| CVE-2026-64962 | 5.1 MEDIUM | Cross-Site Request Forgery (CSRF) in ATutor |
| CVE-2026-64970 | 5.1 MEDIUM | Stored XSS in ATutor |
| CVE-2026-64971 | 4.8 MEDIUM | Reflected XSS in ATutor |
| CVE-2026-64963 | 2.3 LOW | Path Traversal in ATutor |
No comments yet