RSS   Vulnerabilities for 'Submitty'   RSS

2020-05-16
 
CVE-2020-13121

CWE-601
 

 
Submitty through 20.04.01 has an open redirect via authentication/login?old= during an invalid login attempt.

 
2020-05-15
 
CVE-2020-12882

CWE-79
 

 
Submitty through 20.04.01 allows XSS via upload of an SVG document, as demonstrated by an attack by a Student against a Teaching Fellow.

 


Copyright 2024, cxsecurity.com

 

Back to Top