Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2022-39196
Disclosure Date: September 05, 2022 (last updated May 07, 2024)
Blackboard Learn 1.10.1 allows remote authenticated users to read unintended files by entering student credentials and then directly visiting a certain webapps/bbcms/execute/ URL. Note: The vendor disputes this stating this cannot be reproduced.
0
Attacker Value
Unknown
CVE-2021-36746
Disclosure Date: July 20, 2021 (last updated February 23, 2025)
Blackboard Learn through 9.1 allows XSS by an authenticated user via the Assignment Instructions HTML editor.
0
Attacker Value
Unknown
CVE-2021-36747
Disclosure Date: July 20, 2021 (last updated February 23, 2025)
Blackboard Learn through 9.1 allows XSS by an authenticated user via the Feedback to Learner form.
0
Attacker Value
Unknown
CVE-2020-9008
Disclosure Date: February 25, 2020 (last updated February 21, 2025)
Stored Cross-site scripting (XSS) vulnerability in Blackboard Learn/PeopleTool v9.1 allows users to inject arbitrary web script via the Tile widget in the People Tool profile editor.
0
Attacker Value
Unknown
CVE-2017-18262
Disclosure Date: April 30, 2018 (last updated November 26, 2024)
Blackboard Learn (Since at least 17th of October 2017) has allowed Unvalidated Redirects on any signed-in user through its endpoints for handling Shibboleth logins, as demonstrated by a webapps/bb-auth-provider-shibboleth-BBLEARN/execute/shibbolethLogin?returnUrl= URI.
0
Attacker Value
Unknown
CVE-2018-13257
Disclosure Date: April 18, 2018 (last updated November 27, 2024)
The bb-auth-provider-cas authentication module within Blackboard Learn 2018-07-02 is susceptible to HTTP host header spoofing during Central Authentication Service (CAS) service ticket validation, enabling a phishing attack from the CAS server login page.
0
Attacker Value
Unknown
CVE-2007-5227
Disclosure Date: October 05, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in messaging/course/composeMessage.jsp in BlackBoard Learning System 6.3.1.593 and earlier in BlackBoard Academic Suite allow remote attackers to inject arbitrary web script or HTML via the (1) subject_t and (2) body_text parameters. NOTE: vector 2 requires bypassing a client-side security mechanism that attempts to block XSS sequences.
0
Attacker Value
Unknown
CVE-2006-4308
Disclosure Date: August 23, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Blackboard Learning System 6, Blackboard Learning and Community Portal Suite 6.2.3.23, and Blackboard Vista 4 allow remote attackers to inject arbitrary Javascript, VBScript, or HTML via (1) data, (2) vbscript, and (3) malformed javascript URIs in various HTML tags when posting to the Discussion Board.
0