ZeroHour

CVE-2023-34831

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p38
Published
()
Modified
Description

The "Submission Web Form" of Turnitin LTI tool/plugin version 1.3 is affected by HTML Injection attacks. The security issue affects the submission web form ("id" and "title" HTTP POST parameters) where the students submit their reports for similarity/plagiarism checks.

Vendors
odysseycs
Products
ithacalabs turnitin lti
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.