CVE-2023-27008
atutor atutor Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Record summary
CVE-2023-27008 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
A Cross-site scripting (XSS) vulnerability in the function encrypt_password() in login.tmpl.php in ATutor 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the token parameter.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 2, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 18, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
atutorBrowse atutor / atutor | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMATutor < 2.2.1 - Cross Site ScriptingCVSS 6.1
ATutor < 2.2.1 was discovered with a vulnerability, a reflected cross-site scripting (XSS), in ATtutor 2.2.1 via token body parameter.
Impact
Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or defacement of the affected website.
Remediation
Upgrade ATutor to version 2.2.2 or above to mitigate this vulnerability.
Source: ProjectDiscovery