EDX
Edx-platform: vulnerabilidades y CVE
Edx-platform tiene 12 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-22209 | Alta (8.8) | 0.57% | — | 13 ene 2024 | Open edX Platform is a service-oriented platform for authoring and delivering online learning. A user with a JWT and more limited scopes could call endpoints exceeding their access. This vulnerability has been patched… |
| CVE-2021-39248 | Media (6.1) | 0.62% | — | 17 ago 2021 | Open edX through Lilac.1 allows XSS in common/static/common/js/discussion/utils.js via crafted LaTeX content within a discussion. |
| CVE-2018-20859 | Media (6.1) | 1.2% | — | 30 jul 2019 | edx-platform before 2018-07-18 allows XSS via a response to a Chemical Equation advanced problem. |
| CVE-2017-18381 | Alta (7.2) | 1.2% | — | 30 jul 2019 | The installation process in Open edX before 2017-01-10 exposes a MongoDB instance to external connections with default credentials. |
| CVE-2017-18380 | Alta (7.5) | 1.1% | — | 30 jul 2019 | edx-platform before 2017-08-03 allows attackers to trigger password-reset e-mail messages in which the reset link has an attacker-controlled domain name. |
| CVE-2016-10766 | Alta (8.8) | 0.60% | — | 29 jul 2019 | edx-platform before 2016-06-06 allows CSRF. |
| CVE-2016-10765 | Media (5.3) | 0.76% | — | 29 jul 2019 | edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address. |
| CVE-2015-6960 | Media (6.1) | 0.64% | — | 29 jul 2019 | edx-platform before 2015-09-17 allows XSS via a team name. |
| CVE-2015-6253 | Media (5.4) | 0.53% | — | 29 jul 2019 | edx-platform before 2015-08-17 allows XSS in the Studio listing of courses. |
| CVE-2015-5601 | Alta (8.8) | 1.5% | — | 29 jul 2019 | edx-platform before 2015-07-20 allows code execution by privileged users because the course import endpoint mishandles .tar.gz files. |
| CVE-2015-2186 | Alta (7.5) | 1.1% | — | 3 feb 2018 | The Ansible edxapp role in the Configuration Repo in edX allows remote websites to spoof edX accounts by leveraging use of the string literal "False" instead of a boolean False for the CORS_ORIGIN_ALLOW_ALL setting.… |
| CVE-2015-6671 | Media (5.9) | 0.89% | — | 13 mar 2017 | Open edX edx-platform before 2015-08-25 requires use of the database for storage of SAML SSO secrets, which makes it easier for context-dependent attackers to obtain sensitive information by leveraging access to a… |