Vulnerability Description
Autolab is a course management service that enables auto-graded programming assignments. There is an HTML injection vulnerability in version 3.0.1 that can affect instructors and CAs on the grade submissions page. The issue is patched in version 3.0.2. One may apply the patch manually by editing line 589 on `gradesheet.js.erb` to take in feedback as text rather than html.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Autolabproject | Autolab | 3.0.1 |
Related Weaknesses (CWE)
References
- https://github.com/autolab/Autolab/commit/2429983b6caa245fea1b37f0dc236ccbcad955Patch
- https://github.com/autolab/Autolab/security/advisories/GHSA-8qhp-jhhw-45r2Vendor Advisory
FAQ
What is CVE-2024-52585?
CVE-2024-52585 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Autolab is a course management service that enables auto-graded programming assignments. There is an HTML injection vulnerability in version 3.0.1 that can affect instructors and CAs on the grade subm...
How severe is CVE-2024-52585?
CVE-2024-52585 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-52585?
Check the references section above for vendor advisories and patch information. Affected products include: Autolabproject Autolab.