openedx/edx-platform on GitHub
The Open edX LMS & Studio, powering education sites around the world!
CVE History
CVE | Published | CVSS v2 | CVSS v3 |
---|---|---|---|
CVE-2024-22209 | 8.8 HIGH | N/A | |
Open edX Platform is a service-oriented platform for authoring and delivering online learning. A user with a JWT and more limited scopes could call endpoints exceeding their access. This vulnerability has been patched in commit 019888f. | |||
CVE-2018-20859 | 6.1 MEDIUM | 4.3 MEDIUM | |
edx-platform before 2018-07-18 allows XSS via a response to a Chemical Equation advanced problem. | |||
CVE-2017-18380 | 7.5 HIGH | 5 MEDIUM | |
edx-platform before 2017-08-03 allows attackers to trigger password-reset e-mail messages in which the reset link has an attacker-controlled domain name. | |||
CVE-2016-10766 | 8.8 HIGH | 6.8 MEDIUM | |
edx-platform before 2016-06-06 allows CSRF. | |||
CVE-2015-6671 | 5.9 MEDIUM | 4.3 MEDIUM | |
Open edX edx-platform before 2015-08-25 requires use of the database for storage of SAML SSO secrets, which makes it easier for context-dependent attackers to obtain sensitive information by leveraging access to a database backup. |