CVE-2010-0971

ATutor 1.6.4 - Authenticated Cross-Site Scripting in Polls, Groups, and Assignments

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2010-0971. PoCs published by ITSecTeam.

AI-analyzed exploit summary This is a writeup describing multiple XSS vulnerabilities in ATutor 1.6.4, detailing how an authenticated instructor can inject malicious scripts via polls, groups, or assignments. No actual exploit code is provided, only steps to reproduce.

Description

Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.6.4 allow remote authenticated users, with Instructor privileges, to inject arbitrary web script or HTML via the (1) Question and (2) Choice fields in tools/polls/add.php, the (3) Type and (4) Title fields in tools/groups/create_manual.php, and the (5) Title field in assignments/add_assignment.php. NOTE: some of these details are obtained from third party information.

Exploits (1)

exploitdb WRITEUP VERIFIED
by ITSecTeam · textwebappsphp
https://www.exploit-db.com/exploits/11685

This is a writeup describing multiple XSS vulnerabilities in ATutor 1.6.4, detailing how an authenticated instructor can inject malicious scripts via polls, groups, or assignments. No actual exploit code is provided, only steps to reproduce.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: ATutor 1.6.4
Auth required
Prerequisites: Authenticated access as an instructor · Access to the manage section
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/62905
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/38656
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/11685
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/38906
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/62904
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/56852
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/62906

Scores

EPSS 0.0165
EPSS Percentile 73.5%

Details

CWE
CWE-79
Status published
Products (1)
atutor/atutor 1.6.4
Published Mar 16, 2010
Tracked Since Feb 18, 2026