CVE-2024-52585

Autolab is a course management service that enables auto-graded programming assignments. There is an HTML injection vulnerability in version 3.0.1 that can affect instructors and CAs on the grade submissions page. The issue is patched in version 3.0.2. One may apply the patch manually by editing line 589 on `gradesheet.js.erb` to take in feedback as text rather than html.
Configurations

Configuration 1 (hide)

cpe:2.3:a:autolabproject:autolab:3.0.1:*:*:*:*:*:*:*

History

21 Jan 2025, 17:56

Type Values Removed Values Added
References () https://github.com/autolab/Autolab/commit/2429983b6caa245fea1b37f0dc236ccbcad9554c - () https://github.com/autolab/Autolab/commit/2429983b6caa245fea1b37f0dc236ccbcad9554c - Patch
References () https://github.com/autolab/Autolab/security/advisories/GHSA-8qhp-jhhw-45r2 - () https://github.com/autolab/Autolab/security/advisories/GHSA-8qhp-jhhw-45r2 - Vendor Advisory
CPE cpe:2.3:a:autolabproject:autolab:3.0.1:*:*:*:*:*:*:*
First Time Autolabproject autolab
Autolabproject
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

21 Nov 2024, 15:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 4.6
v2 : unknown
v3 : unknown

19 Nov 2024, 16:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.6
Summary
  • (es) Autolab es un servicio de gestión de cursos que permite la calificación automática de tareas de programación. Existe una vulnerabilidad de inyección de HTML en la versión 3.0.1 que puede afectar a los instructores y a los CA en la página de envío de calificaciones. El problema se solucionó en la versión 3.0.2. Se puede aplicar el parche manualmente editando la línea 589 en `gradesheet.js.erb` para que los comentarios se tomen como texto en lugar de HTML.

18 Nov 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-18 21:15

Updated : 2025-01-21 17:56


NVD link : CVE-2024-52585

Mitre link : CVE-2024-52585

CVE.ORG link : CVE-2024-52585


JSON object : View

Products Affected

autolabproject

  • autolab
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')