The Open edX LMS & Studio, powering education sites around the world!

CVE History

CVEPublishedCVSS v2CVSS v3
CVE-2024-222098.8 HIGHN/A
Open edX Platform is a service-oriented platform for authoring and delivering online learning. A user with a JWT and more limited scopes could call endpoints exceeding their access. This vulnerability has been patched in commit 019888f.
CVE-2018-208596.1 MEDIUM4.3 MEDIUM
edx-platform before 2018-07-18 allows XSS via a response to a Chemical Equation advanced problem.
CVE-2017-183807.5 HIGH5 MEDIUM
edx-platform before 2017-08-03 allows attackers to trigger password-reset e-mail messages in which the reset link has an attacker-controlled domain name.
CVE-2016-107668.8 HIGH6.8 MEDIUM
edx-platform before 2016-06-06 allows CSRF.
CVE-2015-66715.9 MEDIUM4.3 MEDIUM
Open edX edx-platform before 2015-08-25 requires use of the database for storage of SAML SSO secrets, which makes it easier for context-dependent attackers to obtain sensitive information by leveraging access to a database backup.