Stored Cross Site Scripting Vulnerability in ATutor by ATutor Development Team
CVE-2026-64970
5.1MEDIUM
What is CVE-2026-64970?
ATutor is affected by a Stored Cross Site Scripting vulnerability within its registration functionality. This flaw allows an attacker to register an account and insert a malicious JavaScript payload into the phone number field. When an authenticated user views the attacker's public profile, the profile template outputs the unencoded phone field, causing the browser to execute the malicious script. This can lead to the theft of sensitive information, such as session cookies, potentially compromising user accounts. The vulnerability has been confirmed in version 2.2.4, while other versions may also be at risk but have not been tested.
Affected Version(s)
ATutor 2.2.4
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Michał Majchrowicz (AFINE Team)
Marcin Wyczechowski (AFINE Team)
