Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2022-39196- — Black board CMS Escalation of Privileges | Kitploit
Tools/GitHubGitHub/dayiliwaseem/cve-2022-39196-
Privilege EscalationVulnerability AnalysisExploitationWeb Application ExploitationData ExfiltrationInformation Gathering
GitHubdayiliwaseem/cve-2022-39196-

CVE-2022-39196-

Black board CMS Escalation of Privileges

View Repository
3 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2022-39196

Black board CMS Escalation of Privileges

Blackboard Learn version 1.10.1 allows remote authenticated users to read unintended files by entering student credentials and then directly visiting a certain webapps/bbcms/execute/ URL.

Additional Information

root@kitploit:~
Step 1: Use a student credentials privilege. Username: ********** & Password: **********, to login. 
Step 2: After successfully login by "STUDENT" account privilege.
Step 3: Then request "URL / Location of vulnerability".
Step 4: Directly without any privilege requirements you will escalated the session from "Student" to "Contest Management System" privileges.

Vulnerability Type

root@kitploit:~
Sensitive Data Exposure

Vendor of Product

root@kitploit:~
Blackboard Learn LMS

Affected Product Code Base

root@kitploit:~
LMS - 1.10.1
CMSMAIN - 1.10.1

Attack Type

root@kitploit:~
Remote

Impact Escalation of Privileges

root@kitploit:~
true

Impact Information Disclosure

root@kitploit:~
true

Attack Vectors

root@kitploit:~
Impact 1: View systems directories such as courses , institution, library and orgs directories & its contains.
Impact 2: Basic & Advance searching over courses , institution, library and orgs directories.
Impact 3: Searching & view about Blackboard LMS institution users.
Impact 4: Download files.

Reference

root@kitploit:~
https://drive.google.com/drive/folders/1gonDDt0sCkpMdPDu_ZVwZ7EfLC8Z4JVn?usp=sharing

Has vendor confirmed or acknowledged the vulnerability?

root@kitploit:~
true

Discoverer

root@kitploit:~
Waseem Dayili
Download Tool