Ironwood
by Open.edx
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-20512 | Med | 0.40 | 6.1 | 0.00 | Mar 18, 2020 | Open edX Ironwood.1 allows support/certificates?course_id= reflected XSS. | ||
| CVE-2020-13145 | Med | 0.35 | 5.4 | 0.01 | May 18, 2020 | Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen. These files can contain JavaScript code and thus lead to Stored XSS. |
- risk 0.40cvss 6.1epss 0.00
Open edX Ironwood.1 allows support/certificates?course_id= reflected XSS.
- risk 0.35cvss 5.4epss 0.01
Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen. These files can contain JavaScript code and thus lead to Stored XSS.