Impact
A path traversal flaw in ATutor allows an authenticated user to read files from other course directories when the AT_FORCE_GET_FILE configuration option is enabled. The vulnerability can expose arbitrary files and reveal the underlying filesystem structure, resulting in unwanted disclosure of sensitive data. The weakness is a classic path traversal flaw (CWE-22).
Affected Systems
ATutor version 2.2.4 has been confirmed vulnerable; the product is no longer actively supported and the vulnerability has not been patched. Other versions were not tested but may also be affected because the same configuration option exists in all releases.
Risk and Exploitability
The CVSS score of 2.3 indicates a low overall severity, and the EPSS score is not available, suggesting no known exploit activity. However, the flaw is exploitable only by authenticated users when AT_FORCE_GET_FILE is active, so the attack vector is local but requires legitimate credentials. The lack of a vendor patch and the product’s unsupported status mean the risk remains, especially in environments where course files contain confidential information.
OpenCVE Enrichment