Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update to version 1.77 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 23 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wisdomgarden
Wisdomgarden tronclass |
|
| Vendors & Products |
Wisdomgarden
Wisdomgarden tronclass |
Mon, 23 Feb 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Feb 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tronclass developed by WisdomGarden has a Insecure Direct Object Reference vulnerability. After obtaining a course ID, authenticated remote attackers to modify a specific parameter to obtain a course invitation code, thereby joining any course. | |
| Title | WisdomGarden|Tronclass - Insecure Direct Object Reference | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2026-02-23T13:46:00.906Z
Reserved: 2026-02-23T01:38:26.604Z
Link: CVE-2026-2997
Updated: 2026-02-23T13:45:34.193Z
Status : Deferred
Published: 2026-02-23T03:15:59.657
Modified: 2026-04-15T00:35:42.020
Link: CVE-2026-2997
No data.
OpenCVE Enrichment
Updated: 2026-04-17T16:30:05Z