Blackboard
blackboard
26 CVEs • 11 products
Products (11)
Click to collapseToggle
Products (11)
Click to collapse
CVEs (26)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Blackboard Learn 1.10.1 allows remote authenticated users to read unintended files by entering student credentials and then directly visiting a certain webapps/bbcms/execute/ URL. Note: The vendor disputes this stating t...Show more |
Blackboard Learn through 9.1 allows XSS by an authenticated user via the Feedback to Learner form. |
Blackboard Learn through 9.1 allows XSS by an authenticated user via the Assignment Instructions HTML editor. |
1Blackboard 1Collaborate Ultra Nov 21, 2024 Mar 2, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Blackboard Collaborate Ultra 20.02 is affected by a cross-site scripting (XSS) vulnerability. The XSS payload will execute on the class room, which leads to stealing cookies from users who join the class. NOTE: Third-par...Show more |
Stored Cross-site scripting (XSS) vulnerability in Blackboard Learn/PeopleTool v9.1 allows users to inject arbitrary web script via the Tile widget in the People Tool profile editor. |
1Blackboard 1Blackboard Learn Nov 21, 2024 Nov 18, 2019 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 The bb-auth-provider-cas authentication module within Blackboard Learn 2018-07-02 is susceptible to HTTP host header spoofing during Central Authentication Service (CAS) service ticket validation, enabling a phishing att...Show more |
1Blackboard 1Blackboard Learn Nov 21, 2024 Apr 30, 2018 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 Blackboard Learn (Since at least 17th of October 2017) has allowed Unvalidated Redirects on any signed-in user through its endpoints for handling Shibboleth logins, as demonstrated by a webapps/bb-auth-provider-shibbolet...Show more |
Cross-site scripting (XSS) vulnerability in Blackboard Vista/CE 8.0 SP6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
The automated-backup functionality in Blackboard Transact Suite (formerly Blackboard Commerce Suite) stores the (1) database username and (2) database password in cleartext in (a) script and (b) batch (.bat) files, which...Show more |
BbtsConnection_Edit.exe in Blackboard Transact Suite (formerly Blackboard Commerce Suite) before 3.6.0.2 relies on field names when determining whether it is appropriate to decrypt a connection.xml field value, which all...Show more |
1Blackboard 1Blackboard Academic Suite Apr 23, 2026 Jul 31, 2008 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Multiple cross-site request forgery (CSRF) vulnerabilities in Blackboard Academic Suite 8.0.260.7 allow remote attackers to hijack the authentication of student users for requests that change configuration and enrollment...Show more |
1Blackboard 1Blackboard Academic Suite Apr 23, 2026 Apr 18, 2008 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The server in Blackboard Academic Suite 7.x stores MD5 password hashes that are provided directly by clients, which makes it easier for remote attackers to access accounts via a modified client that skips the javascript/...Show more |
Multiple cross-site scripting (XSS) vulnerabilities in Blackboard Academic Suite 7.x and earlier, and possibly some 8.0 versions, allow remote attackers to inject arbitrary web script or HTML via (1) the searchText param...Show more |
1Blackboard 1Blackboard Learning And Community Post Systems Apr 23, 2026 Oct 5, 2007 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in messaging/course/composeMessage.jsp in BlackBoard Learning System 6.3.1.593 and earlier in BlackBoard Academic Suite allow remote attackers to inject arbitrary web s...Show more |
1Blackboard 3Blackboard Blackboard Learning And Community Portal SuiteVistaApr 16, 2026 Aug 23, 2006 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in Blackboard Learning System 6, Blackboard Learning and Community Portal Suite 6.2.3.23, and Blackboard Vista 4 allow remote attackers to inject arbitrary Javascript,...Show more |
1Blackboard 1Blackboard Academic Suite Apr 16, 2026 Jul 28, 2006 N/A· v4 N/A· v3 6.0 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Blackboard Academic Suite 6.2.3.23 allows remote authenticated users to inject arbitrary HTML or web script by bypassing client-side validation through disabling JavaScript whe...Show more |
1Blackboard 2Blackboard Blackboard Academic SuiteApr 16, 2026 Feb 1, 2006 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Blackboard Academic Suite 6.0 and earlier does not properly clear session information when de-authenticating a user who is idle, which allows subsequent users to log in as the previous user and gain privileges. NOTE: th...Show more |
Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to list all available categories via a blank category_id parameter to category.pl...Show more |
Cross-site scripting (XSS) vulnerability in Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to inject arbitrary web script or HTM...Show more |
announcement.pl in Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to gain administrator privileges by setting the context parame...Show more |