Oppia

Oppia

3 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Veröffentlicht 03.09.2026 14:12:21
  • Zuletzt bearbeitet 08.10.2026 16:17:55

Oppia's AdminRoleHandler GET endpoint in core/controllers/admin.py is decorated with open_access, allowing any registered user to enumerate privileged accounts and roles. Attackers can query the endpoint with filter_criterion parameters to retrieve u...

Exploit
  • EPSS 0.77%
  • Veröffentlicht 16.08.2023 21:15:09
  • Zuletzt bearbeitet 21.11.2024 08:18:31

Oppia is an online learning platform. When comparing a received CSRF token against the expected token, Oppia uses the string equality operator (`==`), which is not safe against timing attacks. By repeatedly submitting invalid tokens, an attacker can ...

  • EPSS 0.72%
  • Veröffentlicht 08.11.2021 15:15:08
  • Zuletzt bearbeitet 21.11.2024 06:26:40

Oppia 3.1.4 does not verify that certain URLs are valid before navigating to them.