Vulnerability Description
The "Submission Web Form" of Turnitin LTI tool/plugin version 1.3 is affected by HTML Injection attacks. The security issue affects the submission web form ("id" and "title" HTTP POST parameters) where the students submit their reports for similarity/plagiarism checks.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Odysseycs | Ithacalabs Turnitin Lti | 1.3 |
Related Weaknesses (CWE)
References
- https://github.com/IthacaLabs/Turnitin/blob/main/Turnitin_LTI_1.3_HTMLi_CVE-2023ExploitVendor Advisory
- https://github.com/IthacaLabs/Turnitin/blob/main/Turnitin_Submission_Web_Form/Broken Link
- https://github.com/IthacaLabs/Turnitin/blob/main/Turnitin_LTI_1.3_HTMLi_CVE-2023ExploitVendor Advisory
- https://github.com/IthacaLabs/Turnitin/blob/main/Turnitin_Submission_Web_Form/Broken Link
FAQ
What is CVE-2023-34831?
CVE-2023-34831 is a vulnerability with a CVSS score of 5.4 (MEDIUM). The "Submission Web Form" of Turnitin LTI tool/plugin version 1.3 is affected by HTML Injection attacks. The security issue affects the submission web form ("id" and "title" HTTP POST parameters) wher...
How severe is CVE-2023-34831?
CVE-2023-34831 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-34831?
Check the references section above for vendor advisories and patch information. Affected products include: Odysseycs Ithacalabs Turnitin Lti.