Richie是France Université Numérique开源的一个教育内容管理系统。 Richie存在安全漏洞,该漏洞源于sync_course_run_from_request函数中使用非恒定时间==运算符进行HMAC签名验证,可能导致远程攻击者通过测量响应时间差异伪造有效签名并绕过身份验证。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | I discovered a Timing Attack vulnerability in the Richie LMS, developed by France Université Numérique (OpenFUN), and it was assigned the ID CVE-2026-26717 by MITRE. | https://github.com/Rickidevs/CVE-2026-26717 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2026-3172 | 8.1 HIGH | pgvector buffer overflow in parallel HNSW index build |
| CVE-2026-3147 | 5.3 MEDIUM | libvips csvload.c vips_foreign_load_csv_build heap-based overflow |
| CVE-2026-3145 | 5.3 MEDIUM | libvips matrixload.c vips_foreign_load_matrix_header memory corruption |
| CVE-2026-3146 | 3.3 LOW | libvips matrixload.c vips_foreign_load_matrix_header null pointer dereference |
| CVE-2025-69771 | asbplayer 安全漏洞 |
No comments yet