« Volver al listado

EDX

Edx-platform: vulnerabilidades y CVE

Edx-platform tiene 12 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE12
Últimos 12 meses0
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2024-22209Alta (8.8)0.57%—13 ene 2024
Open edX Platform is a service-oriented platform for authoring and delivering online learning. A user with a JWT and more limited scopes could call endpoints exceeding their access. This vulnerability has been patched…
CVE-2021-39248Media (6.1)0.62%—17 ago 2021
Open edX through Lilac.1 allows XSS in common/static/common/js/discussion/utils.js via crafted LaTeX content within a discussion.
CVE-2018-20859Media (6.1)1.2%—30 jul 2019
edx-platform before 2018-07-18 allows XSS via a response to a Chemical Equation advanced problem.
CVE-2017-18381Alta (7.2)1.2%—30 jul 2019
The installation process in Open edX before 2017-01-10 exposes a MongoDB instance to external connections with default credentials.
CVE-2017-18380Alta (7.5)1.1%—30 jul 2019
edx-platform before 2017-08-03 allows attackers to trigger password-reset e-mail messages in which the reset link has an attacker-controlled domain name.
CVE-2016-10766Alta (8.8)0.60%—29 jul 2019
edx-platform before 2016-06-06 allows CSRF.
CVE-2016-10765Media (5.3)0.76%—29 jul 2019
edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address.
CVE-2015-6960Media (6.1)0.64%—29 jul 2019
edx-platform before 2015-09-17 allows XSS via a team name.
CVE-2015-6253Media (5.4)0.53%—29 jul 2019
edx-platform before 2015-08-17 allows XSS in the Studio listing of courses.
CVE-2015-5601Alta (8.8)1.5%—29 jul 2019
edx-platform before 2015-07-20 allows code execution by privileged users because the course import endpoint mishandles .tar.gz files.
CVE-2015-2186Alta (7.5)1.1%—3 feb 2018
The Ansible edxapp role in the Configuration Repo in edX allows remote websites to spoof edX accounts by leveraging use of the string literal "False" instead of a boolean False for the CORS_ORIGIN_ALLOW_ALL setting.…
CVE-2015-6671Media (5.9)0.89%—13 mar 2017
Open edX edx-platform before 2015-08-25 requires use of the database for storage of SAML SSO secrets, which makes it easier for context-dependent attackers to obtain sensitive information by leveraging access to a…

Otros productos de EDX