Back

MEDIUM

WisdomGarden|Tronclass - Insecure Direct Object Reference

Published Feb 23, 2026

Description

Tronclass developed by WisdomGarden has a Insecure Direct Object Reference vulnerability. After obtaining a course ID, authenticated remote attackers to modify a specific parameter to obtain a course invitation code, thereby joining any course.

Affected products

Remediation

Vendor solution

Update to version 1.77 or later.

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner twcert
Published Feb 23, 2026
Updated Feb 23, 2026
Reserved Feb 23, 2026
CISA Vulnrichment
Updated Feb 23, 2026
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner twcert
Published Feb 23, 2026
Updated Feb 23, 2026
Exploited since n/a
EUVD-2026-7601