CVE-2020-9008

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
25/02/2020
Last modified:
09/03/2020

Description

Stored Cross-site scripting (XSS) vulnerability in Blackboard Learn/PeopleTool v9.1 allows users to inject arbitrary web script via the Tile widget in the People Tool profile editor.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:blackboard:blackboard_learn:*:*:*:*:*:*:*:* 9.1 (excluding)
cpe:2.3:a:blackboard:blackboard_learn:9.1:q2_2017:*:*:*:*:*:*
cpe:2.3:a:blackboard:blackboard_learn:9.1:q2_2017_cumulative_update1:*:*:*:*:*:*
cpe:2.3:a:blackboard:blackboard_learn:9.1:q2_2017_cumulative_update2:*:*:*:*:*:*
cpe:2.3:a:blackboard:blackboard_learn:9.1:q2_2017_cumulative_update3:*:*:*:*:*:*
cpe:2.3:a:blackboard:blackboard_learn:9.1:q2_2017_cumulative_update4:*:*:*:*:*:*
cpe:2.3:a:blackboard:blackboard_learn:9.1:q2_2017_cumulative_update5:*:*:*:*:*:*