Autolabproject maintains Autolab, a focused academic laboratory and assignment-management platform that sits in the educational deployment space. Its vulnerability profile centers on web-application security issues spanning path traversal, cross-site scripting, authentication and authorization flaws, and exposure of sensitive data—weakness classes endemic to user-facing web services that handle student submissions and credentials. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Autolabproject over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-49376HIGH Autolab, a course management service that enables auto-graded programming assignments, has misconfigured reset password permissions in version 3.0.0. For email-based accounts, user | Oct 25, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-32676HIGH Autolab is a course management service that enables auto-graded programming assignments. A Tar slip vulnerability was found in the Install assessment functionality of Autolab. To e | May 26, 2023 | 7.2 | 22 | NO | NO |
CVE-2023-32317HIGH Autolab is a course management service that enables auto-graded programming assignments. A Tar slip vulnerability was found in the MOSS cheat checker functionality of Autolab. To e | May 26, 2023 | 7.2 | 22 | NO | NO |
CVE-2022-41956MEDIUM Autolab is a course management service, initially developed by a team of students at Carnegie Mellon University, that enables instructors to offer autograded programming assignment | Jan 14, 2023 | 6.5 | 22 | NO | NO |
CVE-2022-41955HIGH Autolab is a course management service, initially developed by a team of students at Carnegie Mellon University, that enables instructors to offer autograded programming assignment | Jan 14, 2023 | 8.8 | 22 | NO | NO |
CVE-2022-0936MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository autolab/autolab prior to 2.8.0. | Apr 11, 2022 | 5.4 | 21 | NO | NO |
CVE-2024-53260MEDIUM Autolab is a course management service that enables auto-graded programming assignments. A user can modify their first and or last name to include a valid excel / spreadsheet formu | Nov 27, 2024 | 6.8 | 20 | NO | NO |
CVE-2023-44395MEDIUM Autolab is a course management service that enables instructors to offer autograded programming assignments to their students over the Web. Path traversal vulnerabilities were disc | Jan 22, 2024 | 6.5 | 19 | NO | NO |
CVE-2024-52584MEDIUM Autolab is a course management service that enables auto-graded programming assignments. There is a vulnerability in version 3.0.1 where CAs can view or edit the grade for any subm | Nov 18, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-53258MEDIUM Autolab is a course management service that enables auto-graded programming assignments. From Autolab versions v.3.0.0 onward students can download all assignments from another stu | Nov 25, 2024 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Autolabproject.
Media articles that mention a CVE ID that affects a product developed by Autolabproject — matched by CVE ID, not by vendor name.