CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.4. It may be remotely exploitable.
CVE
CVE-2026-2997
Severity
MEDIUM
CVSS
5.4
EPSS
0.17%
Original NVD Description
Tronclass developed by WisdomGarden has a Insecure Direct Object Reference vulnerability. After obtaining a course ID, authenticated remote attackers to modify a specific parameter to obtain a course invitation code, thereby joining any course.