CVE-2024-53260
Last modified
CVE-2024-53260 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. Autolab is a course management service that enables auto-graded programming assignments. A user can modify their first and or last name to include a valid excel / spreadsheet formula. EPSS estimates a 0.46% chance of exploitation in the next 30 days.
Description
Autolab is a course management service that enables auto-graded programming assignments. A user can modify their first and or last name to include a valid excel / spreadsheet formula. When an instructor downloads their course's roster and opens, this name will then be evaluated as a formula. This could lead to leakage of information of students in the course roster by sending the data to a remote endpoint. This issue has been patched in the source code repository and the fix is expected to be released in the next version. Users are advised to manually patch their systems or to wait for the next release. There are no known workarounds for this vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Autolabproject | Autolab | <= 3.0.2 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-53260?
How severe is CVE-2024-53260?
How do I fix CVE-2024-53260?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-53255BoidCMS is a free and open-source flat file CMS for building…5.4
- CVE-2024-53256Rizin is a UNIX-like reverse engineering framework and comma…7.8
- CVE-2024-53257Vitess is a database clustering system for horizontal scalin…4.9
- CVE-2024-53258Autolab is a course management service that enables auto-gra…5.3
- CVE-2024-53259quic-go is an implementation of the QUIC protocol in Go. An …6.5
- CVE-2024-5326The Post Grid Gutenberg Blocks and WordPress Blog Plugin – P…8.8
- CVE-2024-53261SvelteKit is a framework for rapidly developing robust, perf…5.4
- CVE-2024-53262SvelteKit is a framework for rapidly developing robust, perf…5.4
- CVE-2024-53263Git LFS is a Git extension for versioning large files. When …8.5
- CVE-2024-53264bunkerweb is an Open-source and next-generation Web Applicat…5.1
- CVE-2024-53266Discourse is an open source platform for community discussio…5.4
- CVE-2024-53267sigstore-java is a sigstore java client for interacting with…5.5
Are you affected by CVE-2024-53260?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
