Unsupported ATutor Exposed to Reflected XSS

ATutor 2.2.4 is exposed to reflected XSS in its installer and upgrade pages, and the usual fix path is missing because the project is no longer actively supported. That leaves these endpoints as live browser attack surfaces, not just setup-time features. CERT Polska disclosed CVE-2026-6909 in /install/upgrade.php and CVE-2026-6956 in /install/install.php. It confirmed version 2.2.4 as vulnerable and said maintainers were notified early but did not provide a vulnerable range or remediation guidance. For operators still running legacy ATutor, the risk is persistence: a crafted link can run attacker JavaScript in an authenticated user’s browser and act inside the ATutor UI. With no confirmed vendor patch path, exposure does not end with a routine update cycle.

Part of the PlainSec briefing for 2026-05-11

Sources