CVE-2024-22209
Published Jan 13, 2024Open edX Platform is a service-oriented platform for authoring and delivering online learning. A user with a JWT and more limited scopes could call endpoints exceeding their acces…
Vendor archive
19 CVEs tagged to vendor edx — 0 Critical, 7 High, 12 Medium, 0 Low, 0 Unrated.
Open edX Platform is a service-oriented platform for authoring and delivering online learning. A user with a JWT and more limited scopes could call endpoints exceeding their acces…
Open edX platform before 2022-06-06 allows XSS via the "next" parameter in the logout URL.
Open edX through Lilac.1 allows XSS in common/static/common/js/discussion/utils.js via crafted LaTeX content within a discussion.
Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a formula that is exported via the "Course>Data Downloads>Rep…
Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen. These files can contain JavaScript code and thus lead to Stored XSS.
Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New unit>Add new component>Problem button>Adva…
Open edX Ironwood.1 allows support/certificates?user= reflected XSS.
Recommender before 2018-07-18 allows XSS.
edx-platform before 2018-07-18 allows XSS via a response to a Chemical Equation advanced problem.
The installation process in Open edX before 2017-01-10 exposes a MongoDB instance to external connections with default credentials.
edx-platform before 2017-08-03 allows attackers to trigger password-reset e-mail messages in which the reset link has an attacker-controlled domain name.
edx-platform before 2016-06-06 allows CSRF.
edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address.
edx-platform before 2015-09-17 allows XSS via a team name.
edx-platform before 2015-08-17 allows XSS in the Studio listing of courses.
edx-platform before 2015-07-20 allows code execution by privileged users because the course import endpoint mishandles .tar.gz files.
The Ansible edxapp role in the Configuration Repo in edX allows remote websites to spoof edX accounts by leveraging use of the string literal "False" instead of a boolean False fo…
Open edX edx-platform before 2015-08-25 requires use of the database for storage of SAML SSO secrets, which makes it easier for context-dependent attackers to obtain sensitive inf…
lms/templates/footer-edx-new.html in Open edX edx-platform before 2015-01-29 does not properly restrict links on the password-reset page, which allows user-assisted remote attacke…