Fortify
← All intel
NVD/NISTCVE-2026-6909

ATutor Hit by Reflected XSS Flaw

PublishedMay 11, 2026 at 10:16 AM·low

What happened

A reflected cross-site scripting vulnerability (CVE-2026-6909) was disclosed in ATutor's /install/upgrade.php endpoint, allowing attackers to run malicious JavaScript in a victim's browser through a crafted link. Since ATutor is no longer maintained and the vendor did not respond, anyone still running version 2.2.4 (and likely other versions) is at risk. Defenders should retire ATutor installations or isolate them behind authentication and web application firewall rules to block malicious URL parameters.

Tags

#atutor#xss#cve-2026-6909#unpatched#web-vulnerability

Source reference

https://atutor.github.io/

See how Fortify maps this threat to your compliance posture.

14-day free trial · no credit card · HIPAA, SOC 2, ISO 27001, GDPR

Sign Up →