CVE-2024-53260
MEDIUMDescription
Autolab is a course management service that enables auto-graded programming assignments. A user can modify their first and or last name to include a valid excel / spreadsheet formula. When an instructor downloads their course's roster and opens, this name will then be evaluated as a formula. This could lead to leakage of information of students in the course roster by sending the data to a remote endpoint. This issue has been patched in the source code repository and the fix is expected to be released in the next version. Users are advised to manually patch their systems or to wait for the next release. There are no known workarounds for this vulnerability.
Is your site exposed to CVE-2024-53260?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| autolabproject | autolab |
References
Frequently Asked Questions
What is CVE-2024-53260? +
How severe is CVE-2024-53260? +
What products are affected by CVE-2024-53260? +
How do I check if I'm vulnerable to CVE-2024-53260? +
Related Vulnerabilities
In version 8.2.1 of PrestaShop, there is a vulnerability relating to the incorrect sanitisation of elements, caused by inadequate validation …
Data provided in a request performed to the server while activating a new device are put in a database. Other …
phpLDAPadmin since at least version 1.2.0 through the latest version 1.2.6.7 allows users to export elements from the LDAP directory …
Improper Neutralization of Formula Elements in Export CSV feature of Apache Ranger in Apache Ranger Version < 2.6.0. Users are …
There is a CSV injection vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could build malicious data …
A CSV injection vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands via injecting a crafted payload …