CVE-2018-13257: Blackboard Learn
Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.
The bb-auth-provider-cas authentication module within Blackboard Learn 2018-07-02 is susceptible to HTTP host header spoofing during Central Authentication Service (CAS) service ticket validation, enabling a phishing attack from the CAS server login page.
Affected products
- Blackboard Blackboard Learn: version 2018-07-02 only
Published 2019-11-18. Last modified 2026-06-17.