Blackboard Academic Suite multiple scripts cross-site request forgery
| blackboard-multiple-csrf (43986) |
Description:
Blackboard Academic Suite is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input by the update_module.jsp, unenroll.jsp, and enroll_course.pl scripts. By persuading a victim to visit a specially-crafted Web site, a remote attacker could send a malformed HTTP request to cause the victim to enroll users in courses or perform other arbitrary tasks. An attacker could exploit this vulnerability to perform cross-site scripting attacks, Web cache poisoning, and other malicious activities..
Platforms Affected:
- Blackboard, Blackboard Academic Suite 8.0
Remedy:
No remedy available as of June 27, 2009.
Consequences:
Gain Access
References:
- Blackboard Web site, Blackboard Academic Suite at http://www.blackboard.com/products/Academic_Suite/index.
- Mark Janssen Web site, Blackboard cross-site request forgeries at http://ceaseless.ws/bb-csrf/.
- CVE-2008-3421: Multiple cross-site request forgery (CSRF) vulnerabilities in Blackboard Academic Suite 8.0.260.7 allow remote attackers to hijack the authentication of student users for requests that change configuration and enrollments via unspecified input to (1) update_module.jsp, (2) enroll_course.pl, and (3) unenroll.jsp.
- SA31177: Blackboard Academic Suite Cross-Site Request Forgery Vulnerabilities
- SECTRACK ID: 1020559: Blackboard Academic Suite Input Validation Flaws Permit Cross-Site Request Forgery Attacks
Reported:
Jul 25, 2008
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
