Medium severity5.4NVD Advisory· Published May 18, 2020· Updated Jun 17, 2026
CVE-2020-13145
CVE-2020-13145
Description
Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen. These files can contain JavaScript code and thus lead to Stored XSS.
Affected products
4- cpe:2.3:a:edx:open_edx_platform:2.5:*:*:*:*:*:*:*
- Open edX/Studiodescription
Patches
Vulnerability mechanics
References
1- stark0de.com/2020/05/17/openedx-vulnerabilities.htmlnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.