Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Edx Subscribe
Total 18 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-32195 1 Edx 1 Open Edx 2022-06-15 4.3 MEDIUM 6.1 MEDIUM
Open edX platform before 2022-06-06 allows XSS via the "next" parameter in the logout URL.
CVE-2020-13144 1 Edx 1 Open Edx Platform 2022-04-26 6.5 MEDIUM 8.8 HIGH
Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New unit>Add new component>Problem button>Advanced tab>Custom Python evaluated code" screen, edit the problem, and execute Python code. This leads to arbitrary code execution.
CVE-2021-39248 1 Edx 1 Edx-platform 2021-08-25 4.3 MEDIUM 6.1 MEDIUM
Open edX through Lilac.1 allows XSS in common/static/common/js/discussion/utils.js via crafted LaTeX content within a discussion.
CVE-2020-13146 1 Edx 1 Open Edx Platform 2021-07-21 6.8 MEDIUM 8.8 HIGH
Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a formula that is exported via the "Course>Data Downloads>Reports>Download profile info" feature.
CVE-2018-20859 1 Edx 1 Edx-platform 2020-08-24 4.3 MEDIUM 6.1 MEDIUM
edx-platform before 2018-07-18 allows XSS via a response to a Chemical Equation advanced problem.
CVE-2020-13145 1 Edx 1 Open Edx Platform 2020-05-20 3.5 LOW 5.4 MEDIUM
Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen. These files can contain JavaScript code and thus lead to Stored XSS.
CVE-2019-20513 1 Edx 1 Open Edx 2020-03-20 4.3 MEDIUM 6.1 MEDIUM
Open edX Ironwood.1 allows support/certificates?user= reflected XSS.
CVE-2015-6671 1 Edx 1 Edx-platform 2020-01-07 4.3 MEDIUM 5.9 MEDIUM
Open edX edx-platform before 2015-08-25 requires use of the database for storage of SAML SSO secrets, which makes it easier for context-dependent attackers to obtain sensitive information by leveraging access to a database backup.
CVE-2017-18380 1 Edx 1 Edx-platform 2020-01-07 5.0 MEDIUM 7.5 HIGH
edx-platform before 2017-08-03 allows attackers to trigger password-reset e-mail messages in which the reset link has an attacker-controlled domain name.
CVE-2015-6960 1 Edx 1 Edx-platform 2020-01-07 4.3 MEDIUM 6.1 MEDIUM
edx-platform before 2015-09-17 allows XSS via a team name.
CVE-2016-10766 1 Edx 1 Edx-platform 2020-01-07 6.8 MEDIUM 8.8 HIGH
edx-platform before 2016-06-06 allows CSRF.
CVE-2016-10765 1 Edx 1 Edx-platform 2020-01-07 5.0 MEDIUM 5.3 MEDIUM
edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address.
CVE-2017-18381 2 Edx, Mongodb 2 Edx-platform, Mongodb 2020-01-07 6.5 MEDIUM 9.1 CRITICAL
The installation process in Open edX before 2017-01-10 exposes a MongoDB instance to external connections with default credentials.
CVE-2015-5601 1 Edx 1 Edx-platform 2020-01-07 6.5 MEDIUM 8.8 HIGH
edx-platform before 2015-07-20 allows code execution by privileged users because the course import endpoint mishandles .tar.gz files.
CVE-2015-6253 1 Edx 1 Edx-platform 2020-01-07 3.5 LOW 5.4 MEDIUM
edx-platform before 2015-08-17 allows XSS in the Studio listing of courses.
CVE-2018-20858 1 Edx 1 Recommender 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
Recommender before 2018-07-18 allows XSS.
CVE-2015-2186 1 Edx 2 Configuration, Edx-platform 2018-03-02 5.0 MEDIUM 7.5 HIGH
The Ansible edxapp role in the Configuration Repo in edX allows remote websites to spoof edX accounts by leveraging use of the string literal "False" instead of a boolean False for the CORS_ORIGIN_ALLOW_ALL setting. Note: this vulnerability was fixed on 2015-03-06, but the version number was not changed.
CVE-2015-2286 1 Edx 1 Open Edx 2016-03-22 4.3 MEDIUM 6.5 MEDIUM
lms/templates/footer-edx-new.html in Open edX edx-platform before 2015-01-29 does not properly restrict links on the password-reset page, which allows user-assisted remote attackers to discover password-reset tokens by reading a referer log after a victim navigates from this page to a social-sharing site.