PT-2026-79018 · Atutor · Atutor

·

CVE-2026-64970

·

Published

2026-08-20

·

Updated

2026-08-20

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions ATutor version 2.2.4
Description Stored Cross Site Scripting (XSS) exists in the registration functionality. An attacker can register a new account and inject a JavaScript payload into the phone field. When an authenticated user views the attacker's public profile, the profile template renders the phone value without output encoding, causing the browser to execute the payload and potentially allowing the theft of the user's session cookie.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-64970

Affected Products

Atutor