Skip to main content

Vendor/product archive

edx / open_edx_platform CVEs

Beta · best-effort

3 CVEs tagged to edx / open_edx_platform0 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2020-13146

Published May 18, 2020

Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a formula that is exported via the "Course>Data Downloads>Rep…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13145

Published May 18, 2020

Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen. These files can contain JavaScript code and thus lead to Stored XSS.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13144

Published May 18, 2020

Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New unit>Add new component>Problem button>Adva…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1