Trivantis develops the CourseMill learning management system, a web-based educational platform whose vulnerability profile centers on application-layer input-handling and session-management weaknesses, including cross-site scripting, SQL injection, CSRF, and improper input validation. These recurring weakness classes reflect the data-input and user-interaction demands of a hosted e-learning environment. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Trivantis over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-3599HIGH userlogin.jsp in Coursemill Learning Management System (LMS) 6.6 and 6.8 allows remote attackers to gain privileges via a modified user-role value to home.html. | Sep 6, 2013 | 9.3 | 23 | NO | NO |
CVE-2013-5708MEDIUM Coursemill Learning Management System (LMS) 6.8 constructs secret tokens based on time values, which makes it easier for remote attackers to conduct cross-site request forgery (CSR | Sep 6, 2013 | 6.8 | 21 | NO | NO |
CVE-2013-3600HIGH Coursemill Learning Management System (LMS) 6.6 allows remote authenticated users to gain privileges via a modified userid value to unspecified functions. | Sep 6, 2013 | 8.5 | 21 | NO | NO |
CVE-2013-3602HIGH SQL injection vulnerability in admindocumentworker.jsp in Coursemill Learning Management System (LMS) 6.6 allows remote authenticated users to execute arbitrary SQL commands via th | Sep 6, 2013 | 7.5 | 19 | NO | NO |
CVE-2007-6338HIGH SQL injection vulnerability in userlogin.jsp in Trivantis CourseMill Enterprise Learning Management System 4.1 SP4 allows remote attackers to execute arbitrary SQL commands via the | Dec 15, 2007 | 7.5 | 19 | NO | NO |
CVE-2013-3605MEDIUM Cross-site request forgery (CSRF) vulnerability in Coursemill Learning Management System (LMS) 6.6 allows remote attackers to hijack the authentication of arbitrary users via vecto | Sep 6, 2013 | 6.8 | 18 | NO | NO |
CVE-2013-3603MEDIUM Cross-site scripting (XSS) vulnerability in Coursemill Learning Management System (LMS) 6.6 allows remote attackers to inject arbitrary web script or HTML via vectors related to er | Sep 6, 2013 | 4.3 | 18 | NO | NO |
CVE-2013-5707MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Coursemill Learning Management System (LMS) 6.8 allow remote attackers to inject arbitrary web script or HTML via crafted inp | Sep 6, 2013 | 4.3 | 17 | NO | NO |
CVE-2013-5706MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Coursemill Learning Management System (LMS) 6.8 allow remote attackers to inject arbitrary web script or HTML via vectors rel | Sep 6, 2013 | 4.3 | 17 | NO | NO |
CVE-2013-3601MEDIUM Coursemill Learning Management System (LMS) 6.6 does not properly restrict JSP function calls, which allows remote authenticated users to perform arbitrary JSP operations by levera | Sep 6, 2013 | 6.0 | 17 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Trivantis.
Media articles that mention a CVE ID that affects a product developed by Trivantis — matched by CVE ID, not by vendor name.