Webct operates a learning management and assessment platform, with the observed vulnerability surface concentrating in its core LMS product and related assessment tools such as Respondus. The recurring signal centers on web-application input-handling issues, particularly cross-site scripting weaknesses endemic to user-facing educational software. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webct over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2001-1003MEDIUM Respondus 1.1.2 for WebCT uses weak encryption to remember usernames and passwords, which allows local users who can read the WEBCT.SVR file to decrypt the passwords and gain addit | Aug 31, 2001 | 4.6 | 26 | NO | YES |
CVE-2008-1225MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in WebCT Campus Edition 4.1.5.8, when "Don't wrap text" is enabled, allow remote authenticated users to inject arbitrary web scr | Mar 10, 2008 | 4.3 | 21 | NO | YES |
CVE-2005-1076MEDIUM Cross-site scripting (XSS) vulnerability in the discussion board functionality for WebCT Campus Edition 4.1 allows remote attackers to inject arbitrary web script or HTML via the m | May 2, 2005 | 4.3 | 21 | NO | YES |
CVE-2004-1872MEDIUM Cross-site scripting (XSS) vulnerability in WebCT Campus Edition 4.1.1.5 allows remote attackers to inject arbitrary web script or HTML via the @import URL function in a CSS style | Mar 29, 2004 | 4.3 | 21 | NO | YES |
CVE-2004-2015MEDIUM Cross-site scripting (XSS) vulnerability in WebCT Campus Edition allows remote attackers to inject arbitrary HTML or web script via (1) iframe, (2) img, or (3) object tags. | Dec 31, 2004 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webct.
Media articles that mention a CVE ID that affects a product developed by Webct — matched by CVE ID, not by vendor name.