CVE-2017-18262

Blackboard Learn (Since at least 17th of October 2017) has allowed Unvalidated Redirects on any signed-in user through its endpoints for handling Shibboleth logins, as demonstrated by a webapps/bb-auth-provider-shibboleth-BBLEARN/execute/shibbolethLogin?returnUrl= URI.
References
Link Resource
http://seclists.org/fulldisclosure/2018/Apr/57 Mailing List Third Party Advisory
http://www.securitytracker.com/id/1040767 Third Party Advisory VDB Entry
https://ethan.pm/blackboard.txt Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:blackboard:blackboard_learn:*:*:*:*:*:*:*:*
cpe:2.3:a:blackboard:blackboard_learn:9.1:q2_2016:*:*:*:*:*:*
cpe:2.3:a:blackboard:blackboard_learn:9.1:q2_2017:*:*:*:*:*:*
cpe:2.3:a:blackboard:blackboard_learn:9.1:q4_2015:*:*:*:*:*:*
cpe:2.3:a:blackboard:blackboard_learn:9.1:q4_2016:*:*:*:*:*:*
cpe:2.3:a:blackboard:blackboard_learn:9.1:q4_2017:*:*:*:*:*:*

History

No history.

Information

Published : 2018-04-30 13:29

Updated : 2024-02-04 19:46


NVD link : CVE-2017-18262

Mitre link : CVE-2017-18262

CVE.ORG link : CVE-2017-18262


JSON object : View

Products Affected

blackboard

  • blackboard_learn
CWE
CWE-20

Improper Input Validation

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')