BlackBoard CourseInfo 4.0 does not properly authenticate users, which allows local users to modify CourseInfo database information and gain privileges by directly calling the supporting CGI programs such as user_update_passwd.pl and user_update_admin.pl.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Courseinfo | Blackboard | 4.0 (including) | 4.0 (including) |
Courseinfo | Blackboard | unix (including) | unix (including) |