← Back

Rcos

rcos

4 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Submitty
submitty

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Rcos
1Submitty
Jun 17, 2026
Nov 2, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Submitty before v22.06.00 is vulnerable to Incorrect Access Control. An attacker can delete any post in the forum by modifying request parameter.
1Rcos
1Submitty
Jun 17, 2026
Nov 2, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Submitty before v22.06.00 is vulnerable to Cross Site Scripting (XSS). An attacker can create a malicious link in the forum that leads to XSS.
1Rcos
1Submitty
Jun 17, 2026
May 16, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Submitty through 20.04.01 has an open redirect via authentication/login?old= during an invalid login attempt.
1Rcos
1Submitty
Jun 17, 2026
May 15, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Submitty through 20.04.01 allows XSS via upload of an SVG document, as demonstrated by an attack by a Student against a Teaching Fellow.