Open Edx
by Edx
Source repositories
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-32195 | Med | 0.40 | 6.1 | 0.02 | Jun 9, 2022 | Open edX platform before 2022-06-06 allows XSS via the "next" parameter in the logout URL. | ||
| CVE-2019-20513 | Med | 0.40 | 6.1 | 0.00 | Mar 19, 2020 | Open edX Ironwood.1 allows support/certificates?user= reflected XSS. | ||
| CVE-2015-2286 | Med | 0.35 | 6.5 | 0.02 | Mar 19, 2016 | lms/templates/footer-edx-new.html in Open edX edx-platform before 2015-01-29 does not properly restrict links on the password-reset page, which allows user-assisted remote attackers to discover password-reset tokens by reading a referer log after a victim navigates from this… |
- risk 0.40cvss 6.1epss 0.02
Open edX platform before 2022-06-06 allows XSS via the "next" parameter in the logout URL.
- risk 0.40cvss 6.1epss 0.00
Open edX Ironwood.1 allows support/certificates?user= reflected XSS.
- risk 0.35cvss 6.5epss 0.02
lms/templates/footer-edx-new.html in Open edX edx-platform before 2015-01-29 does not properly restrict links on the password-reset page, which allows user-assisted remote attackers to discover password-reset tokens by reading a referer log after a victim navigates from this…