First published: Mon Apr 30 2018(Updated: )
Blackboard Learn (Since at least 17th of October 2017) has allowed Unvalidated Redirects on any signed-in user through its endpoints for handling Shibboleth logins, as demonstrated by a webapps/bb-auth-provider-shibboleth-BBLEARN/execute/shibbolethLogin?returnUrl= URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Blackboard Blackboard Learn | <=9.1 | |
Blackboard Blackboard Learn | =9.1-q2_2016 | |
Blackboard Blackboard Learn | =9.1-q2_2017 | |
Blackboard Blackboard Learn | =9.1-q4_2015 | |
Blackboard Blackboard Learn | =9.1-q4_2016 | |
Blackboard Blackboard Learn | =9.1-q4_2017 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18262 is a vulnerability in Blackboard Learn that allows unvalidated redirects on any signed-in user through its endpoints for handling Shibboleth logins.
Blackboard Learn versions 9.1 and 9.1-q2_2016, 9.1-q2_2017, 9.1-q4_2015, 9.1-q4_2016, and 9.1-q4_2017 are affected by CVE-2017-18262.
CVE-2017-18262 has a severity level of 6.1, which is considered medium severity.
The CWEs associated with CVE-2017-18262 are CWE-20 (Improper Input Validation) and CWE-601 (URL Redirection to Untrusted Site ('Open Redirect')).
You can find more information about CVE-2017-18262 at the following references: [1] [2] [3].