CVE-2008-3421
Multiple cross-site request forgery (CSRF) vulnerabilities in Blackboard Academic Suite 8.0.260.7 allow remote attackers to hijack the authentication of student users for requests that change configuration and enrollments via unspecified input to (1)…
Does this matter?
Lower severity and a low EPSS score (0.53%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in Blackboard Academic Suite 8.0.260.7 allow remote attackers to hijack the authentication of student users for requests that change configuration and enrollments via unspecified input to (1) update_module.jsp, (2) enroll_course.pl, and (3) unenroll.jsp.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 0.53% probability · 43th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- blackboard/blackboard academic suite
- Source
- cve@mitre.org
References
- http://ceaseless.ws/bb-csrf/URL Repurposed
- http://secunia.com/advisories/31177Vendor Advisory
- http://www.securitytracker.com/id?1020559
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43986
- http://ceaseless.ws/bb-csrf/URL Repurposed
- http://secunia.com/advisories/31177Vendor Advisory
- http://www.securitytracker.com/id?1020559
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43986
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.