The bb-auth-provider-cas authentication module within Blackboard Learn 2018-07-02 is susceptible to HTTP host header spoofing during Central Authentication Service (CAS) service ticket validation, enabling a phishing attack from the CAS server login page.
View Full Alert
Related Posts
CVE-2018-17792MDaemon Webmail (formerly WorldClient) has CSRF. View Full Alert
CVE-2018-14919LOYTEC LGATE-902 6.3.2 devices allow XSS. View Full Alert
CVE-2018-14918LOYTEC LGATE-902 6.3.2 devices allow Directory Traversal. View Full Alert