Tronclass developed by WisdomGarden has a Insecure Direct Object Reference vulnerability. After obtaining a course ID, authenticated remote attackers to modify a specific parameter to obtain a course invitation code, thereby joining any course.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Update to version 1.77 or later.
Workaround
No workaround given by the vendor.
References
History
Mon, 23 Feb 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tronclass developed by WisdomGarden has a Insecure Direct Object Reference vulnerability. After obtaining a course ID, authenticated remote attackers to modify a specific parameter to obtain a course invitation code, thereby joining any course. | |
| Title | WisdomGarden|Tronclass - Insecure Direct Object Reference | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2026-02-23T01:55:37.610Z
Reserved: 2026-02-23T01:38:26.604Z
Link: CVE-2026-2997
No data.
Status : Received
Published: 2026-02-23T03:15:59.657
Modified: 2026-02-23T03:15:59.657
Link: CVE-2026-2997
No data.
OpenCVE Enrichment
No data.
Weaknesses