SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-64968

MEDIUM · CVSS 5.1 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

ATutor is susceptible to server-side request forgery (SSRF) through its import functionalities, allowing authenticated administrators to access arbitrary internal HTTP endpoints, cloud metadata services, or local files if the PHP environment allows URL wrappers. This vulnerability poses a medium risk as it could lead to unauthorized data exposure or manipulation. Organizations still using version 2.2.4 or potentially other untested versions should prioritize remediation efforts, as the product is no longer actively supported and lacks fixes for this issue.

CVE
CVE-2026-64968
Severity
MEDIUM
CVSS
5.1
EPSS
0.29%

Original NVD Description

ATutor is vulnerable to Server-Side request forgery in import functionalities. An authenticated administrator can make the server request arbitrary internal HTTP endpoints, cloud metadata services, or local files via file:// if the PHP environment permits URL wrappers. Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.