CVE-2008-3421 Information

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in Blackboard Academic Suite 8.0.260.7 allow remote attackers to hijack the authentication of student users for requests that change configuration and enrollments via unspecified input to (1) update_module.jsp (2) enroll_course.pl and (3) unenroll.jsp.

Reference

http://ceaseless.ws/bb-csrf/ http://secunia.com/advisories/31177 http://www.securitytracker.com/id?1020559 https://exchange.xforce.ibmcloud.com/vulnerabilities/43986

Share on: