Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
open edx vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2024-22209
Open edX Platform is a service-oriented platform for authoring and delivering online learning. A user with a JWT and more limited scopes could call endpoints exceeding their access. This vulnerability has been patched in commit 019888f.
Edx Edx-platform
NA
CVE-2023-23611
LTI Consumer XBlock implements the consumer side of the LTI specification enabling integration of third-party LTI provider tools. Versions 7.0.0 and above, before 7.2.2, are vulnerable to Missing Authorization. Any LTI tool that is integrated with on the Open edX platform can pos...
Openedx Xblock-lti-consumer
383
VMScore
CVE-2022-32195
Open edX platform prior to 2022-06-06 allows XSS via the "next" parameter in the logout URL.
Edx Open Edx
383
VMScore
CVE-2021-39248
Open edX through Lilac.1 allows XSS in common/static/common/js/discussion/utils.js via crafted LaTeX content within a discussion.
Edx Edx-platform -
605
VMScore
CVE-2020-13146
Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a formula that is exported via the "Course>Data Downloads>Reports>Download profile info" feature.
Edx Open Edx Platform 2.5
578
VMScore
CVE-2020-13144
Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New unit>Add new component>Problem button>Advanced tab>Custom Python evaluated code" screen, edit the problem, and e...
Edx Open Edx Platform 2.5
312
VMScore
CVE-2020-13145
Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen. These files can contain JavaScript code and thus lead to Stored XSS.
Edx Open Edx Platform 2.5
383
VMScore
CVE-2019-20513
Open edX Ironwood.1 allows support/certificates?user= reflected XSS.
Edx Open Edx 2019-03-15
383
VMScore
CVE-2019-20512
Open edX Ironwood.1 allows support/certificates?course_id= reflected XSS.
Open.edx Ironwood .1
578
VMScore
CVE-2017-18381
The installation process in Open edX prior to 2017-01-10 exposes a MongoDB instance to external connections with default credentials.
Edx Edx-platform
1 Github repository
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
validation
CVE-2012-1823
malicious code
CVE-2024-5770
CVE-2023-45866
CVE-2024-35687
local users
CVE-2024-31246
CVE-2024-35730
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »