Packback is an educational technology vendor with a narrow focus on learning-management integrations, particularly its LTI 1.3 tool library used in classroom platforms. Its observed vulnerability surface centers on authentication and cryptographic weaknesses—capture-replay attacks, insufficient randomness, and use of broken or risky cryptographic schemes—that are characteristic of authentication-protocol implementation in middleware components. Current exploitation activity, severity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Packback over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-31158HIGH LTI 1.3 Tool Library is a library used for building IMS-certified LTI 1.3 tool providers in PHP. Prior to version 5.0, the Nonce Claim Value was not being validated against the non | Jul 15, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-31157HIGH LTI 1.3 Tool Library is a library used for building IMS-certified LTI 1.3 tool providers in PHP. Prior to version 5.0, the function used to generate random nonces was not sufficien | Jul 15, 2022 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Packback.
Media articles that mention a CVE ID that affects a product developed by Packback — matched by CVE ID, not by vendor name.