Edx / Edx-Platform
12 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-22209 | XBlock custom auth does not respect JWT Scopes | HIGH | 8.8 | Jan 13, 2024 |
| CVE-2021-39248 | Open edX through Lilac.1 allows XSS in common/static/common/js/discussion/utils.js via crafted LaTeX content within a discussion. | MEDIUM | 6.1 | Aug 17, 2021 |
| CVE-2018-20859 | edx-platform before 2018-07-18 allows XSS via a response to a Chemical Equation advanced problem. | MEDIUM | 6.1 | Jul 30, 2019 |
| CVE-2017-18381 | The installation process in Open edX before 2017-01-10 exposes a MongoDB instance to external connections with default credentials. | HIGH | 7.2 | Jul 30, 2019 |
| CVE-2017-18380 | edx-platform before 2017-08-03 allows attackers to trigger password-reset e-mail messages in which the reset link has an attacker-controlled domain name. | HIGH | 7.5 | Jul 30, 2019 |
| CVE-2016-10766 | edx-platform before 2016-06-06 allows CSRF. | HIGH | 8.8 | Jul 29, 2019 |
| CVE-2016-10765 | edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address. | MEDIUM | 5.3 | Jul 29, 2019 |
| CVE-2015-5601 | edx-platform before 2015-07-20 allows code execution by privileged users because the course import endpoint mishandles .tar.gz files. | HIGH | 8.8 | Jul 29, 2019 |
| CVE-2015-6253 | edx-platform before 2015-08-17 allows XSS in the Studio listing of courses. | MEDIUM | 5.4 | Jul 29, 2019 |
| CVE-2015-6960 | edx-platform before 2015-09-17 allows XSS via a team name. | MEDIUM | 6.1 | Jul 29, 2019 |
| CVE-2015-2186 | The Ansible edxapp role in the Configuration Repo in edX allows remote websites to spoof edX accounts by leveraging use of the string literal "False" instead o… | HIGH | 7.5 | Feb 3, 2018 |
| CVE-2015-6671 | Open edX edx-platform before 2015-08-25 requires use of the database for storage of SAML SSO secrets, which makes it easier for context-dependent attackers to… | MEDIUM | 5.9 | Mar 13, 2017 |
Showing 1 to 12 of 12 CVEs