PT-2022-24797 · Blackboard · Blackboard Learn
Waseem Dayili
·
Published
2022-09-04
·
Updated
2024-08-03
·
CVE-2022-39196
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Blackboard Learn version 1.10.1
Description
The issue allows remote authenticated users to read unintended files by entering student credentials and then directly visiting a certain "webapps/bbcms/execute/" URL. The vendor disputes this, stating it cannot be reproduced.
Recommendations
For Blackboard Learn version 1.10.1, as a temporary workaround, consider restricting access to the "webapps/bbcms/execute/" URL until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Blackboard Learn