Skip to main content

Vendor archive

edx CVEs

Beta · best-effort

19 CVEs tagged to vendor edx0 Critical, 7 High, 12 Medium, 0 Low, 0 Unrated.

CVE-2024-22209

Published Jan 13, 2024

Open edX Platform is a service-oriented platform for authoring and delivering online learning. A user with a JWT and more limited scopes could call endpoints exceeding their acces…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32195

Published Jun 9, 2022

Open edX platform before 2022-06-06 allows XSS via the "next" parameter in the logout URL.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39248

Published Aug 17, 2021

Open edX through Lilac.1 allows XSS in common/static/common/js/discussion/utils.js via crafted LaTeX content within a discussion.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13146

Published May 18, 2020

Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a formula that is exported via the "Course>Data Downloads>Rep…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13145

Published May 18, 2020

Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen. These files can contain JavaScript code and thus lead to Stored XSS.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13144

Published May 18, 2020

Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New unit>Add new component>Problem button>Adva…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-20513

Published Mar 19, 2020

Open edX Ironwood.1 allows support/certificates?user= reflected XSS.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20859

Published Jul 30, 2019

edx-platform before 2018-07-18 allows XSS via a response to a Chemical Equation advanced problem.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18381

Published Jul 30, 2019

The installation process in Open edX before 2017-01-10 exposes a MongoDB instance to external connections with default credentials.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2017-18380

Published Jul 30, 2019

edx-platform before 2017-08-03 allows attackers to trigger password-reset e-mail messages in which the reset link has an attacker-controlled domain name.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10765

Published Jul 29, 2019

edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-6253

Published Jul 29, 2019

edx-platform before 2015-08-17 allows XSS in the Studio listing of courses.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5601

Published Jul 29, 2019

edx-platform before 2015-07-20 allows code execution by privileged users because the course import endpoint mishandles .tar.gz files.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-2186

Published Feb 3, 2018

The Ansible edxapp role in the Configuration Repo in edX allows remote websites to spoof edX accounts by leveraging use of the string literal "False" instead of a boolean False fo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-6671

Published Mar 13, 2017

Open edX edx-platform before 2015-08-25 requires use of the database for storage of SAML SSO secrets, which makes it easier for context-dependent attackers to obtain sensitive inf…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2286

Published Mar 19, 2016

lms/templates/footer-edx-new.html in Open edX edx-platform before 2015-01-29 does not properly restrict links on the password-reset page, which allows user-assisted remote attacke…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-19 of 19 CVEsPage 1 of 1