Autolab · Autolab · CVE-2024-52585
**Name of the Vulnerable Software and Affected Versions**
Autolab version 3.0.1
**Description**
The issue concerns an HTML injection vulnerability that can affect instructors and CAs on the grade submissions page. This vulnerability is patched in version 3.0.2.
**Recommendations**
For Autolab version 3.0.1, apply the patch manually by editing line 589 on `gradesheet.js.erb` to take in feedback as text rather than html.