CVE-2018-13257: Blackboard Learn

Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.

The bb-auth-provider-cas authentication module within Blackboard Learn 2018-07-02 is susceptible to HTTP host header spoofing during Central Authentication Service (CAS) service ticket validation, enabling a phishing attack from the CAS server login page.

Affected products

  • Blackboard Blackboard Learn: version 2018-07-02 only

Published 2019-11-18. Last modified 2026-06-17.