ATutor is vulnerable to Missing Authorization Check on Test and Question Import endpoints. A low-privileged authenticated user (e.g. a student) enrolled in a course can bypass authorization checks by sending requests directly to the backend import endpoints, allowing the unauthorized import of tests and questions within a course.
Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-20 14:17
Updated : 2026-08-28 15:26
NVD link : CVE-2026-64965
Mitre link : CVE-2026-64965
CVE.ORG link : CVE-2026-64965
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
