Autolab is a course management service that enables auto-graded programming assignments. There is an HTML injection vulnerability in version 3.0.1 that can affect instructors and CAs on the grade submissions page. The issue is patched in version 3.0.2. One may apply the patch manually by editing line 589 on `gradesheet.js.erb` to take in feedback as text rather than html.
History

Tue, 21 Jan 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Autolabproject
Autolabproject autolab
CPEs cpe:2.3:a:autolabproject:autolab:3.0.1:*:*:*:*:*:*:*
Vendors & Products Autolabproject
Autolabproject autolab
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Fri, 22 Nov 2024 12:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N'}


Tue, 19 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 18 Nov 2024 21:00:00 +0000

Type Values Removed Values Added
Description Autolab is a course management service that enables auto-graded programming assignments. There is an HTML injection vulnerability in version 3.0.1 that can affect instructors and CAs on the grade submissions page. The issue is patched in version 3.0.2. One may apply the patch manually by editing line 589 on `gradesheet.js.erb` to take in feedback as text rather than html.
Title Autolab has HTML Injection Vulnerability
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 1.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-11-21T14:47:11.984Z

Reserved: 2024-11-14T15:05:46.766Z

Link: CVE-2024-52585

cve-icon Vulnrichment

Updated: 2024-11-19T15:30:52.620Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-18T21:15:07.183

Modified: 2025-01-21T17:56:12.597

Link: CVE-2024-52585

cve-icon Redhat

No data.