CVE-2019-7172: Atutor
Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.
A stored-self XSS exists in ATutor through v2.2.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Real Name field to /mods/_core/users/admins/my_edit.php.
Affected products
- Atutor Atutor: up to and including 2.2.4
Published 2019-01-29. Last modified 2026-06-17.