CVE-2013-3601: Trivantis Coursemill Learning Management System

Medium severity, CVSS 6.0. EPSS: 1% chance of exploitation in the next 30 days.

Coursemill Learning Management System (LMS) 6.6 does not properly restrict JSP function calls, which allows remote authenticated users to perform arbitrary JSP operations by leveraging the Student role and providing an op parameter.

Affected products

  • Trivantis Coursemill Learning Management System: version 6.6 only

Published 2013-09-06. Last modified 2026-06-16.