S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-27008 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in ATutor affects v. 2.2.1.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-27008
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

A Cross-site scripting (XSS) vulnerability in the function encrypt_password() in login.tmpl.php in ATutor 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the token parameter.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

ATutor is an open-source learning management system (LMS) designed to provide a robust online platform for educators to create, deliver and manage courses for their students. This product is widely utilized by different institutions, such as schools, colleges and universities, around the world. With its easy-to-use interface, ATutor offers various features that aid in collaborative learning and the distribution of educational resources. These features include blended learning, multimedia content management and social networking.

The CVE-2023-27008 vulnerability is a cross-site scripting (XSS) vulnerability found in ATutor's encrypt_password() function in login.tmpl.php, making it prone to arbitrary script injection and HTML abuse. Attackers can utilize this vulnerability to insert malicious code into the system, allowing them to steal information such as passwords, confidential data and user sessions. Additionally, this vulnerability makes it possible for cybercriminals to execute unauthorized actions in accounts, which can lead to serious consequences such as data breaches and account takeovers.

Exploiting the vulnerability could lead to several severe consequences. Cybercriminals may use this vulnerability to steal valuable and sensitive information, such as login credentials, that can be used for targeted phishing attacks, identity theft or fraud. They may also be able to gain unauthorized access to private user accounts, manipulate user data, or disrupt and corrupt the system's functionalities. Moreover, the attackers can utilize this vulnerability to execute remote code, which can endanger critical assets in the system.

s4e.io's pro features utilize advanced security testing techniques to identify and report vulnerabilities quickly and efficiently. With tools such as web application scanners and manual testing, the platform enables customers to assess digital assets for vulnerabilities and take corrective measures immediately. By reading this article, you can gain knowledge of this vulnerability and take the necessary precautions to strengthen the security of your digital assets.

 

REFERENCES

Solution Advice

To avoid this vulnerability, precautionary measures need to be taken seriously. Here are some ways to protect against this vulnerability:

  • Update the system to its latest version, as ATutor has released a fix for this vulnerability.
  • Regularly monitor the system logs and intrusion detection systems to identify and respond to any attacks or unusual activities.
  • Use a web application firewall (WAF) to detect and block malicious traffic targeting the system.
  • Train employees on avoiding phishing attacks and the importance of maintaining password hygiene.
  • Conduct vulnerability assessments and penetration testing on the system regularly to identify and address any new vulnerabilities that may arise.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-27008 scanner - Cross-Site Scripting (XSS) vulnerability in ATutor | S4E