科研速览 · Science Skim继续刷下去 · Keep skimming →
◆ International Journal of Science Technology Engineering and Mathematics2026-08-31· Audit

CVE-based security audit of open-source learning management systems in higher education using CVSS and OWASP

Melissa Guillermo, Eduardo Yu II, Dr. Reagan Ricafort

原始摘要(英文原文)· Original abstract
This study examined publicly disclosed Common Vulnerabilities and Exposures (CVE) records for Moodle, Chamilo, Canvas LMS, Open edX, and Sakai to assess their value for higher education security governance. A non-intrusive secondary-data audit analyzed 236 CVEs from 2018 to 3 June 2026 using platform, National Vulnerability Database (NVD) Published Date year, revised CVSS severity categories, and OWASP Top 10:2021 classifications. Six zero-score records were separated from low severity. A sensitivity analysis compared the full corpus with 211 NVD API-verified records. A blinded independent IT-faculty coder recoded 24 records; severity agreement was 100.0% (Cohen's kappa = 1.000), and OWASP agreement was 91.7% (Cohen's kappa = 0.814). Moodle and Chamilo represented 91.5% of the corpus, a disclosure-weighted pattern rather than a product ranking. A03 Injection (54.2%) and A01 Broken Access Control (31.4%) dominated. Among records with numeric CVSS scores, including six zero-score records, high/critical proportions were 45.3% (67/148) in the full corpus and 44.9% (66/147) in the NVD-verified subset. Canvas and Sakai findings were interpreted cautiously because of small denominators. Public CVE evidence is affected by disclosure asymmetry, incomplete CVSS metadata, NVD non-returned records, and deployment differences. Because identifiable CVSS version/vector metadata were not preserved, severity comparisons are descriptive rather than version-normalized. The audit offers a reproducible governance framework linking vulnerability patterns to patching, authorization review, content-ingestion controls, plugin governance, and supplier accountability without treating raw CVE counts as inherent security rankings.
读原文 · Read the paper ↗

AI 追问PRO

登录后使用 AI 追问

讨论区

登录后参与讨论

相关论文 · Related

CVE-based security audit of open-source learning management systems in higher education using CVSS and OWASP — 科研速览 Science Skim