SafeExamBrowser / seb-win-refactoring

Safe Exam Browser for Windows.
https://www.safeexambrowser.org/news_en.html
Mozilla Public License 2.0
184 stars 123 forks source link

Unauthorized Access to Social Media Platforms via External Links on Moodle within SEB #673

Closed ormoon-ll closed 1 year ago

ormoon-ll commented 1 year ago

When using Safe Exam Browser in conjunction with Moodle, a vulnerability has been discovered that allows users to gain unauthorized access to social media platforms. This deviates from the expected behavior where such platforms should be inaccessible to maintain the integrity of the online examination environment.

Steps to Reproduce:

Launch SEB and log in to Moodle. 387327724_3494347877546383_1115170513625979743_n

Locate and click on any external link provided within Moodle course materials or pages. 387331201_1070355697239393_7602685126386082699_n

Once on the external website, navigate to the bottom (or any section) where social media links are typically provided.

387463559_1752845665155093_6726343780625554699_n

387455755_1759080337863522_5151250378602029994_n

Click on any of these social media links, which leads to the respective social media login page. 368788430_1646289085861083_4169834762758091206_n

At this point, a user can log in to the social media platform, thus bypassing SEB's intended restrictions.

387526737_1379375422928689_1344087292148934995_n

Version Information

This vulnerability suggests that SEB's restriction mechanism can be bypassed by a chain of legitimate website navigations initiated from within Moodle.

dbuechel commented 1 year ago

You'll need to make sure that users cannot do this yourself. You can achieve this by e.g. not displaying links allowing to leave your LMS or adding URL filter rules to your exam configuration. For more information on both topics, please refer to https://safeexambrowser.org/developer/seb-integration.html resp. https://safeexambrowser.org/windows/win_usermanual_en.html#NetworkPane.