CVE-2015-10040
MEDIUMgitlearn < 2015-06-09 - Injection in Escape Sequence Handler
Title source: llmDescription
A vulnerability was found in gitlearn. It has been declared as problematic. This vulnerability affects the function getGrade/getOutOf of the file scripts/config.sh of the component Escape Sequence Handler. The manipulation leads to injection. The attack can be initiated remotely. The patch is identified as 3faa5deaa509012069afe75cd03c21bda5050a64. It is recommended to apply a patch to fix this issue. VDB-218302 is the identifier assigned to this vulnerability.
References (4)
Core 4
Core References
Third Party Advisory vdb-entry
technical-description
https://vuldb.com/?id.218302
Third Party Advisory signature
permissions-required
https://vuldb.com/?ctiid.218302
Exploit, Patch, Third Party Advisory issue-tracking
https://github.com/mikeizbicki/gitlearn/pull/31
Patch, Third Party Advisory patch
https://github.com/mikeizbicki/gitlearn/commit/3faa5deaa509012069afe75cd03c21bda5050a64
Scores
CVSS v3
5.4
EPSS
0.0078
EPSS Percentile
50.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-74
CWE-116
Status
published
Products (1)
gitlearn_project/gitlearn
< 2015-06-09
Published
Jan 13, 2023
Tracked Since
Feb 18, 2026