Vulnerabilità ed exploit · Attacco ad app web
ATutor 2.2.4 è esposto a Reflected XSS nelle pagine dell'installer e dell'upgrade, e il normale percorso di correzione manca perché il progetto non è più supportato attivamente. Ciò lascia questi endpoint come superfici di attacco browser attive, non solo funzionalità usate in fase di configurazione.
1 fonte · 11 mag
CERT Polska
Vulnerabilities in ATutor software
CERT Polska has received a report about 2 vulnerabilities (CVE-2026-6909 and CVE-2026-6956) found in ATutor software.
originalePart of the PlainSec briefing for 2026-05-11
Every edition of this story: ATutor non supportato esposto a Reflected XSS