LTI 1.3 Grade Pass Back Implementation has Missing Authorization Vulnerability
Any LTI tool that is integrated with on the Open edX platform can post a grade back for any LTI XBlock so long as it knows the resource_link_id (i.e. block location) for that XBlock. The impact is a loss of integrity for LTI XBlock grades.