ATutor 1.5.1 is susceptible to SQL injection, credential disclosure, user impersonation, and remote code execution attacks.