go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

WisdomGarden|Tronclass - Insecure Direct Object Reference

TVN ID TVN-202602005
CVE ID CVE-2026-2997
CVSS 5.4 (Medium)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Affected Products Tronclass version 1.74 and earlier
Description Tronclass developed by WisdomGarden has a Insecure Direct Object Reference vulnerability. After obtaining a course ID, authenticated remote attackers to modify a specific parameter to obtain a course invitation code, thereby joining any course.
Solution Update to version 1.77 or later.
Credit yochan06(ICEDTEA)
Public Date 2026-02-23
Top