CVE-2017-18262

Blackboard Learn (Since at least 17th of October 2017) has allowed Unvalidated Redirects on any signed-in user through its endpoints for handling Shibboleth logins, as demonstrated by a webapps/bb-auth-provider-shibboleth-BBLEARN/execute/shibbolethLogin?returnUrl= URI.
References
Link Resource
https://ethan.pm/blackboard.txt Third Party Advisory
http://seclists.org/fulldisclosure/2018/Apr/57 Mailing List Third Party Advisory
http://www.securitytracker.com/id/1040767 Third Party Advisory VDB Entry
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:blackboard:blackboard_learn:9.1:q4_2015:*:*:*:*:*:*
cpe:2.3:a:blackboard:blackboard_learn:9.1:q4_2017:*:*:*:*:*:*
cpe:2.3:a:blackboard:blackboard_learn:9.1:q2_2017:*:*:*:*:*:*
cpe:2.3:a:blackboard:blackboard_learn:9.1:q4_2016:*:*:*:*:*:*
cpe:2.3:a:blackboard:blackboard_learn:9.1:q2_2016:*:*:*:*:*:*
cpe:2.3:a:blackboard:blackboard_learn:*:*:*:*:*:*:*:*

Information

Published : 2018-04-30 06:29

Updated : 2018-06-12 11:15


NVD link : CVE-2017-18262

Mitre link : CVE-2017-18262


JSON object : View

CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

CWE-20

Improper Input Validation

Advertisement

dedicated server usa

Products Affected

blackboard

  • blackboard_learn