CVE-2023-27008 identifies a Cross-site scripting (XSS) vulnerability in the encrypt_password() function of ATutor 2.2.1, allowing remote attackers to inject arbitrary web scripts or HTML via the token parameter. This vulnerability is rated Medium severity (CVSS 6.1) with a network attack vector and low complexity, requiring no privileges but user interaction, potentially leading to low confidentiality and integrity impacts. Despite not being in CISA's KEV catalog, it is listed on the Hot List as "Active" and has a high EPSS score, indicating a significant probability of exploitation. Exploit code is publicly available via Nuclei templates, and community discussions confirm the existence of exploit code, suggesting active interest and potential for widespread exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.2.1CPE matchmatch criteria | cpe:2.3:a:atutor:atutor:2.2.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.