← Back

Inducer

inducer

5 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Relate
relate

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Inducer
1Relate
Jun 17, 2026
May 8, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
RELATE is a web-based courseware package. Prior to commit 2f68e16, there is a timing attack vulnerability in course/auth.py — check_sign_in_key(). This issue has been patched via commit 2f68e16.
1Inducer
1Relate
Jun 17, 2026
Apr 26, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted payload to the Batch-Issue Exam Tickets function.
1Inducer
1Relate
Jun 17, 2026
Apr 26, 2024
N/A· v4
6.0 MEDIUM· v3
N/A· v2
Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1, allows remote attackers to execute arbitrary code via a crafted payload to the Markup Sandbox feature.
1Inducer
1Relate
Jun 17, 2026
Apr 22, 2024
N/A· v4
2.6 LOW· v3
N/A· v2
Cross Site Scripting vulnerability in inducer relate before v.2024.1 allows a remote attacker to escalate privileges via a crafted payload to the Answer field of InlineMultiQuestion parameter on Exam function.
1Inducer
1Relate
Jun 17, 2026
Apr 22, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted payload to the Page Sandbox feature.