Submitty是一套开源的课程管理系统。该系统支持课程管理、作业提交、考试和分级系统等功能。 Submitty 20.04.01及之前版本中的登录页面存在输入验证错误漏洞。该漏洞源于网络系统或产品未对输入的数据进行正确的验证。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Submitty through 20.04.01 contains an open redirect vulnerability via authentication/login?old= during an invalid login attempt. An attacker can redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-13121.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2020-13118 | Mikrotik-Router-Monitoring-System SQL注入漏洞 | |
| CVE-2020-13111 | NaviServer 缓冲区错误漏洞 | |
| CVE-2020-13110 | kerberos package for Node.js 代码问题漏洞 | |
| CVE-2020-13109 | SETA Morita Shogi 64 缓冲区错误漏洞 |
No comments yet