Reflected Cross-Site Scripting Vulnerability in ATutor by@ATutor
CVE-2020-23341

6.1MEDIUM

Key Information:

Vendor

Atutor

Status
Vendor
CVE Published:
17 August 2021

What is CVE-2020-23341?

This vulnerability in ATutor 2.2.4 allows attackers to exploit reflected cross-site scripting (XSS) in the /header.tmpl.php component. By crafting a specific payload, an attacker can execute arbitrary web scripts or HTML, which could lead to unauthorized actions or theft of sensitive information. Proper input validation and sanitization measures are essential to mitigate this risk.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.