Rcos develops the Submitty assignment and assessment platform, a course-management tool focused on educational and academic deployments. The observed vulnerability profile centers on application-layer input and authorization issues, including cross-site scripting, missing authorization checks, and open-redirect flaws that are typical of web-facing educational software. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rcos over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-13121MEDIUM Submitty through 20.04.01 has an open redirect via authentication/login?old= during an invalid login attempt. | May 16, 2020 | 6.1 | 25 | NO | YES |
CVE-2020-12882MEDIUM Submitty through 20.04.01 allows XSS via upload of an SVG document, as demonstrated by an attack by a Student against a Teaching Fellow. | May 15, 2020 | 5.4 | 23 | NO | YES |
CVE-2023-43193MEDIUM Submitty before v22.06.00 is vulnerable to Cross Site Scripting (XSS). An attacker can create a malicious link in the forum that leads to XSS. | Nov 2, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-43194MEDIUM Submitty before v22.06.00 is vulnerable to Incorrect Access Control. An attacker can delete any post in the forum by modifying request parameter. | Nov 2, 2023 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rcos.
Media articles that mention a CVE ID that affects a product developed by Rcos — matched by CVE ID, not by vendor name.