PT-2026-79011 · Atutor · Atutor

·

CVE-2026-64963

·

Published

2026-08-20

·

Updated

2026-08-20

CVSS v4.0

2.3

Low

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions ATutor version 2.2.4
Description A path traversal vulnerability allows an authenticated user to access files from other course directories. This occurs when the AT FORCE GET FILE configuration option is enabled, potentially leading to unauthorized file access and disclosure of the filesystem structure. Path traversal is a flaw that allows an attacker to access files and directories that are stored outside the web root folder.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Disable the AT FORCE GET FILE configuration option to mitigate the risk of exploitation.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-64963

Affected Products

Atutor