Impact
ATutor contains a reflected cross‑site scripting flaw in its restore feature. A malicious actor can embed a crafted URL that, when opened by a victim, injects arbitrary JavaScript into the victim's browser. The vulnerability permits code execution only in the context of the user who clicks the link, allowing a potential attacker to steal credentials, hijack sessions, or perform other malicious actions within the victim's browser session. The issue is a classic case of CWE‑79. The vendor has stopped actively supporting ATutor and has not applied a fix.
Affected Systems
The affected product is ATutor ATutor, specifically version 2.2.4, which has been confirmed to be vulnerable. While the vulnerability has not been formally tested on other releases, the code path that triggers the XSS is present in earlier versions, so those may also be compromised. ATutor is no longer maintained, which means no updates or security patches will be released.
Risk and Exploitability
With a CVSS score of 4.8, the technical severity is considered moderate, and the vulnerability is not listed in CISA's KEV catalog. The EPSS score is not available, leaving the exploitation probability uncertain. The likely attack vector is a social‑engineering scenario where an attacker distributes the malicious URL via email, messaging, or a compromised site. If a user follows the link, the injected code runs with the permissions of the victim's browser, potentially compromising session data or conducting further attacks. Since the product is unmaintained and only a single tested version is vulnerable, the overall risk to systems that have migrated to newer platforms is lower, but any remaining ATutor installations remain exposed until remedied.
OpenCVE Enrichment