CVE-2026-64966

ATutor is vulnerable to a Path Traversal vulnerability in ZIP extraction functionality. An attacker with instructor privileges can upload and extract a specially crafted ZIP archive, causing files to be written outside the intended extraction directory. This allows an attacker to place a server-executable .phtml file in the web root and achieve remote code execution with web server privileges on the underlying server. Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-08-20 14:17

Updated : 2026-08-28 15:26


NVD link : CVE-2026-64966

Mitre link : CVE-2026-64966

CVE.ORG link : CVE-2026-64966


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')