| CVE ID | CVE-2026-64960 |
| Publication date | 20 August 2026 |
| Vendor | ATutor |
| Product | ATutor |
| Vulnerable versions | 2.2.4 |
| Vulnerability type (CWE) | Unrestricted upload of file with dangerous type (CWE-434) |
| Report source | Report to CERT Polska |
| CVE ID | CVE-2026-64961 |
| Publication date | 20 August 2026 |
| Vendor | ATutor |
| Product | ATutor |
| Vulnerable versions | 2.2.4 |
| Vulnerability type (CWE) | Authorization bypass through User-Controlled key (CWE-639) |
| Report source | Report to CERT Polska |
| CVE ID | CVE-2026-64962 |
| Publication date | 20 August 2026 |
| Vendor | ATutor |
| Product | ATutor |
| Vulnerable versions | 2.2.4 |
| Vulnerability type (CWE) | Cross-Site request forgery (CSRF) (CWE-352) |
| Report source | Report to CERT Polska |
| CVE ID | CVE-2026-64963 |
| Publication date | 20 August 2026 |
| Vendor | ATutor |
| Product | ATutor |
| Vulnerable versions | 2.2.4 |
| Vulnerability type (CWE) | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) |
| Report source | Report to CERT Polska |
| CVE ID | CVE-2026-64964 |
| Publication date | 20 August 2026 |
| Vendor | ATutor |
| Product | ATutor |
| Vulnerable versions | 2.2.4 |
| Vulnerability type (CWE) | Generation of Predictable Numbers or Identifiers (CWE-340) |
| Report source | Report to CERT Polska |
| CVE ID | CVE-2026-64965 |
| Publication date | 20 August 2026 |
| Vendor | ATutor |
| Product | ATutor |
| Vulnerable versions | 2.2.4 |
| Vulnerability type (CWE) | Missing Authorization (CWE-862) |
| Report source | Report to CERT Polska |
| CVE ID | CVE-2026-64966 |
| Publication date | 20 August 2026 |
| Vendor | ATutor |
| Product | ATutor |
| Vulnerable versions | 2.2.4 |
| Vulnerability type (CWE) | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) |
| Report source | Report to CERT Polska |
| CVE ID | CVE-2026-64967 |
| Publication date | 20 August 2026 |
| Vendor | ATutor |
| Product | ATutor |
| Vulnerable versions | 2.2.4 |
| Vulnerability type (CWE) | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) |
| Report source | Report to CERT Polska |
| CVE ID | CVE-2026-64968 |
| Publication date | 20 August 2026 |
| Vendor | ATutor |
| Product | ATutor |
| Vulnerable versions | 2.2.4 |
| Vulnerability type (CWE) | Server-Side request forgery (SSRF) (CWE-918) |
| Report source | Report to CERT Polska |
| CVE ID | CVE-2026-64969 |
| Publication date | 20 August 2026 |
| Vendor | ATutor |
| Product | ATutor |
| Vulnerable versions | 2.2.4 |
| Vulnerability type (CWE) | Authorization bypass through User-Controlled key (CWE-639) |
| Report source | Report to CERT Polska |
| CVE ID | CVE-2026-64970 |
| Publication date | 20 August 2026 |
| Vendor | ATutor |
| Product | ATutor |
| Vulnerable versions | 2.2.4 |
| Vulnerability type (CWE) | Improper neutralization of input during web page generation ('cross-site scripting') (CWE-79) |
| Report source | Report to CERT Polska |
| CVE ID | CVE-2026-64971 |
| Publication date | 20 August 2026 |
| Vendor | ATutor |
| Product | ATutor |
| Vulnerable versions | 2.2.4 |
| Vulnerability type (CWE) | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') (CWE-79) |
| Report source | Report to CERT Polska |
| CVE ID | CVE-2026-64972 |
| Publication date | 20 August 2026 |
| Vendor | ATutor |
| Product | ATutor |
| Vulnerable versions | 2.2.4 |
| Vulnerability type (CWE) | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') (CWE-79) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerabilities in ATutor software and participated in coordination of their disclosure.
The vulnerability CVE-2026-64960: ATutor Gameme module allows users to upload files of any type and extension without restriction. Due to improper handling of file uploads, files are stored in a web-accessible location before their content is validated. An authenticated attacker who knows a valid course_id can upload a server-executable malicious script. The uploaded file can then be requested over HTTP, resulting in remote code execution as the web server process user. In most cases, course_id=0 can be used, as it commonly represents the global context.
The vulnerability CVE-2026-64961: ATutor is vulnerable to Authentication Bypass. Although a token validation check is present in the auto-login functionality, the values required for token validation remain uninitialized in certain code paths. An unauthenticated attacker who can determine a user's identifier and registration timestamp can generate a valid token and authenticate as an existing user, including administrator, without knowing the password.
The vulnerability CVE-2026-64962: ATutor is vulnerable to Cross-Site Request Forgery (CSRF) in profile update functionality. An attacker can craft a malicious website which, when visited by an authenticated victim, submits a forged request to the system. Due to the lack of proper CSRF token implementation, the forged request is processed successfully, allowing an attacker to modify profile fields of an existing user.
The vulnerability CVE-2026-64963: A Path Traversal vulnerability in ATutor allows an authenticated user to access files from other course directories when the AT_FORCE_GET_FILE configuration option is enabled. This can lead to unauthorized access to files and disclosure of information about the filesystem structure.
The vulnerability CVE-2026-64964: ATutor generates predictable email confirmation tokens due to the use of insufficiently random values in the account confirmation functionality. Due to the use of predictable values related to user registration, an attacker who knows or can predict these values can guess valid account activation tokens. This allows an attacker to activate an unconfirmed account without access to the victim's email inbox.
The vulnerability CVE-2026-64965: ATutor is vulnerable to Missing Authorization Check on Test and Question Import endpoints. A low-privileged authenticated user (e.g. a student) enrolled in a course can bypass authorization checks by sending requests directly to the backend import endpoints, allowing the unauthorized import of tests and questions within a course.
The vulnerability CVE-2026-64966: ATutor is vulnerable to a Path Traversal vulnerability in ZIP extraction functionality. An attacker with instructor privileges can upload and extract a specially crafted ZIP archive, causing files to be written outside the intended extraction directory. This allows an attacker to place a server-executable .phtml file in the web root and achieve remote code execution with web server privileges on the underlying server.
The vulnerability CVE-2026-64967: A Path Traversal vulnerability in ATutor's error log viewer allows an attacker with administrative privileges to access arbitrary files outside the intended logs directory. This can lead to unauthorized access to sensitive files and other resources accessible to the web server process.
The vulnerability CVE-2026-64968: ATutor is vulnerable to Server-Side request forgery in import functionalities. An authenticated administrator can make the server request arbitrary internal HTTP endpoints, cloud metadata services, or local files via file:// if the PHP environment permits URL wrappers.
The vulnerability CVE-2026-64969: ATutor is vulnerable to Insecure Direct Object Reference (IDOR) attack in profile picture related endpoints. Any authenticated user, including a student, can supply another user's member_id in a POST request to the profile album endpoint and permanently delete that user's profile picture, including those of instructors and administrators.
The vulnerability CVE-2026-64970: ATutor is vulnerable to Stored Cross Site Scripting in registration functionality. An attacker can register a new account and enter a JavaScript payload in the phone field during registration. When any authenticated user visits the attacker's public profile, the profile template echoes the phone value without output encoding and the browser executes the payload leading to the theft of user's session cookie.
The vulnerability CVE-2026-64971: ATutor is vulnerable to Reflected XSS in restore functionality. An attacker can provide a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser.
The vulnerability CVE-2026-64972: ATutor is vulnerable to Reflected XSS via popup parameter in preview.php. An authenticated attacker can inject a double quote into the popup parameter, break out of the attribute value, and append a new event handler such as onload. The related preview_top.php file sanitises these parameters, but that does not prevent XSS in the parent frameset rendered by preview.php itself.
Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.
Credits
We thank Michał Majchrowicz and Marcin Wyczechowski from AFINE Team for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.