PT-2026-79015 · Atutor · Atutor
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ATutor version 2.2.4
Description
A path traversal vulnerability exists in the error log viewer. This flaw allows an attacker with administrative privileges to access arbitrary files outside the intended logs directory, potentially leading to unauthorized access to sensitive files and other resources accessible to the web server process. Path traversal is a technique used to access files and directories that are stored outside the web root folder by manipulating variables that reference files with dot-dot-slash (../) sequences.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Atutor