CVE-2022-39196

Blackboard Learn 1.10.1 allows remote authenticated users to read unintended files by entering student credentials and then directly visiting a certain webapps/bbcms/execute/ URL. Note: The vendor disputes this stating this cannot be reproduced.
References
Link Resource
https://github.com/DayiliWaseem/CVE-2022-39196- Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:blackboard:blackboard_learn:1.10.1:*:*:*:*:*:*:*

History

06 May 2024, 22:15

Type Values Removed Values Added
Summary (en) Blackboard Learn 1.10.1 allows remote authenticated users to read unintended files by entering student credentials and then directly visiting a certain webapps/bbcms/execute/ URL. (en) Blackboard Learn 1.10.1 allows remote authenticated users to read unintended files by entering student credentials and then directly visiting a certain webapps/bbcms/execute/ URL. Note: The vendor disputes this stating this cannot be reproduced.

08 Aug 2023, 14:22

Type Values Removed Values Added
CWE CWE-863 NVD-CWE-noinfo

Information

Published : 2022-09-05 00:15

Updated : 2024-08-03 12:15


NVD link : CVE-2022-39196

Mitre link : CVE-2022-39196

CVE.ORG link : CVE-2022-39196


JSON object : View

Products Affected

blackboard

  • blackboard_learn