4.3
CVE-2008-3421
- EPSS 0.53%
- Veröffentlicht 31.07.2008 17:41:00
- Zuletzt bearbeitet 16.06.2026 22:55:47
- CVE-Watchlists
- Unerledigt
Multiple cross-site request forgery (CSRF) vulnerabilities in Blackboard Academic Suite 8.0.260.7 allow remote attackers to hijack the authentication of student users for requests that change configuration and enrollments via unspecified input to (1) update_module.jsp, (2) enroll_course.pl, and (3) unenroll.jsp.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Blackboard ≫ Blackboard Academic Suite Version8.0.260.7
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.53% | 0.405 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
http://ceaseless.ws/bb-csrf/
http://secunia.com/advisories/31177
http://www.securitytracker.com/id?1020559
https://exchange.xforce.ibmcloud.com/vulnerabilities/43986