NVD/NISTCVE-2026-6909
ATutor Hit by Reflected XSS Flaw
PublishedMay 11, 2026 at 10:16 AM·low
What happened
A reflected cross-site scripting vulnerability (CVE-2026-6909) was disclosed in ATutor's /install/upgrade.php endpoint, allowing attackers to run malicious JavaScript in a victim's browser through a crafted link. Since ATutor is no longer maintained and the vendor did not respond, anyone still running version 2.2.4 (and likely other versions) is at risk. Defenders should retire ATutor installations or isolate them behind authentication and web application firewall rules to block malicious URL parameters.
Tags
#atutor#xss#cve-2026-6909#unpatched#web-vulnerability
Source reference
https://atutor.github.io/ ↗See how Fortify maps this threat to your compliance posture.
14-day free trial · no credit card · HIPAA, SOC 2, ISO 27001, GDPR
Sign Up →