Inducer

Relate

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.49%
  • Veröffentlicht 27.05.2026 18:31:55
  • Zuletzt bearbeitet 01.06.2026 18:31:49

RELATE is a web-based courseware package. Prior to commit d66ba5659b459bf1ba56b7109b5f9ecf197cbefb, RELATE LMS configures its Celery workers to accept and deserialize untrusted 'pickle' data. An attacker who can reach the message broker can execute a...

  • EPSS 0.31%
  • Veröffentlicht 27.05.2026 18:30:27
  • Zuletzt bearbeitet 01.06.2026 18:26:25

RELATE is a web-based courseware package. Versions prior to commit 555f0efb1c5bd7531c07cd73724d7e566a81f620 have a stored cross-site scripting vulnerability that allows any enrolled student to execute arbitrary JavaScript in an administrator's browse...

  • EPSS 0.36%
  • Veröffentlicht 08.05.2026 15:16:43
  • Zuletzt bearbeitet 12.05.2026 21:09:52

RELATE is a web-based courseware package. Prior to commit 2f68e16, there is a timing attack vulnerability in course/auth.py — check_sign_in_key(). This issue has been patched via commit 2f68e16.

  • EPSS 0.26%
  • Veröffentlicht 07.05.2026 13:35:02
  • Zuletzt bearbeitet 07.05.2026 15:53:49

RELATE is a web-based courseware package. Prior to commit 2f68e16, RELATE is vulnerable to predictable token generation in auth.py's make_sign_in_key() function and exam.py's gen_ticket_code() function. This issue has been patched via commit 2f68e16.

  • EPSS 0.8%
  • Veröffentlicht 26.04.2024 04:15:09
  • Zuletzt bearbeitet 30.06.2025 14:11:32

Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1, allows remote attackers to execute arbitrary code via a crafted payload to the Markup Sandbox feature.

Exploit
  • EPSS 1.11%
  • Veröffentlicht 26.04.2024 04:15:09
  • Zuletzt bearbeitet 17.12.2025 16:16:04

Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted payload to the Batch-Issue Exam Tickets function.

Exploit
  • EPSS 0.5%
  • Veröffentlicht 22.04.2024 20:15:07
  • Zuletzt bearbeitet 13.06.2025 16:10:19

Cross Site Scripting vulnerability in inducer relate before v.2024.1 allows a remote attacker to escalate privileges via a crafted payload to the Answer field of InlineMultiQuestion parameter on Exam function.

Exploit
  • EPSS 1.1%
  • Veröffentlicht 22.04.2024 19:15:46
  • Zuletzt bearbeitet 13.06.2025 16:11:59

An issue in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted payload to the Page Sandbox feature.