Support Us — Your donation helps us keep running

Goal: 1000 CNY,Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2024-53258
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
download_all_submissions allows student to download another student's submissions in Autolab
Source: NVD (National Vulnerability Database)
Vulnerability Description
Autolab is a course management service that enables auto-graded programming assignments. From Autolab versions v.3.0.0 onward students can download all assignments from another student, as long as they are logged in, using the download_all_submissions feature. This can allow for leakage of submissions to unauthorized users, such as downloading submissions from other students in the class, or even instructor test submissions, given they know their user IDs. This issue has been patched in commit `1aa4c769` which is not yet in a release version, but is expected to be included in version 3.0.3. Users are advised to either manually patch or to wait for version 3.0.3. As a workaround administrators can disable the feature.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
侵犯隐私
Source: NVD (National Vulnerability Database)
Vulnerability Title
Autolab 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Autolab是Autolab开源的一项课程管理服务。支持自动评分的编程作业。 Autolab 3.0.0版本存在安全漏洞,该漏洞源于学生能使用download_all_submissions功能从其他学生那里下载所有作业,会导致提交内容泄露给未经授权的用户。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
autolabAutolab >= 3.0.0, before commit 1aa4c7690892fb458d2c61ff86739f368e34769d -
II. Public POCs for CVE-2024-53258
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2024-53258
Please Login to view more intelligence information
New Vulnerabilities
V. Comments for CVE-2024-53258

No comments yet


Leave a comment