edx kayıtları
edx üreticisine ait 19 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %5,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-20 Improper Input Validation2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-284 Improper Access Control2
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
19 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
38İzleyin | CVE-2020-13144Kavram kanıtı | Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New uniedx · open edx platform · CWE-94 | Yüksek8,8 | — | %11,0 | 18 May 2020 |
35İzleyin | CVE-2015-5601İstismar yok | edx-platform before 2015-07-20 allows code execution by privileged users because the course import endpoint mishandles .tar.gz files.edx · edx-platform · CWE-434 | Yüksek8,8 | — | %1,5 | 29 Tem 2019 |
35İzleyin | CVE-2020-13146İstismar yok | Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a formula that is expoedx · open edx platform · CWE-1236 | Yüksek8,8 | — | %1,1 | 18 May 2020 |
35İzleyin | CVE-2016-10766İstismar yok | edx-platform before 2016-06-06 allows CSRF.edx · edx-platform · CWE-352 | Yüksek8,8 | — | %0,6 | 29 Tem 2019 |
35İzleyin | CVE-2024-22209İstismar yok | XBlock custom auth does not respect JWT Scopesedx · edx-platform · CWE-284 | Yüksek8,8 | — | %0,6 | 13 Oca 2024 |
30İzleyin | CVE-2015-2186İstismar yok | The Ansible edxapp role in the Configuration Repo in edX allows remote websites to spoof edX accounts by leveraging use of the string literaedx · configuration · CWE-20 | Yüksek7,5 | — | %1,1 | 3 Şub 2018 |
30İzleyin | CVE-2017-18380İstismar yok | edx-platform before 2017-08-03 allows attackers to trigger password-reset e-mail messages in which the reset link has an attacker-controllededx · edx-platform · CWE-284 | Yüksek7,5 | — | %1,1 | 30 Tem 2019 |
28İzleyin | CVE-2017-18381İstismar yok | The installation process in Open edX before 2017-01-10 exposes a MongoDB instance to external connections with default credentials.edx · edx-platform | Yüksek7,2 | — | %1,2 | 30 Tem 2019 |
27İzleyin | CVE-2015-2286İstismar yok | lms/templates/footer-edx-new.html in Open edX edx-platform before 2015-01-29 does not properly restrict links on the password-reset page, whedx · open edx · CWE-200 | Orta6,5 | — | %2,0 | 19 Mar 2016 |
25İzleyin | CVE-2022-32195Kavram kanıtı | Open edX platform before 2022-06-06 allows XSS via the "next" parameter in the logout URL.edx · open edx · CWE-79 | Orta6,1 | — | %2,4 | 9 Haz 2022 |
24İzleyin | CVE-2018-20859İstismar yok | edx-platform before 2018-07-18 allows XSS via a response to a Chemical Equation advanced problem.edx · edx-platform · CWE-79 | Orta6,1 | — | %1,2 | 30 Tem 2019 |
24İzleyin | CVE-2018-20858İstismar yok | Recommender before 2018-07-18 allows XSS.edx · recommender · CWE-79 | Orta6,1 | — | %0,9 | 9 Ağu 2019 |
24İzleyin | CVE-2015-6960İstismar yok | edx-platform before 2015-09-17 allows XSS via a team name.edx · edx-platform · CWE-79 | Orta6,1 | — | %0,6 | 29 Tem 2019 |
24İzleyin | CVE-2021-39248İstismar yok | Open edX through Lilac.1 allows XSS in common/static/common/js/discussion/utils.js via crafted LaTeX content within a discussion.edx · edx-platform · CWE-79 | Orta6,1 | — | %0,6 | 17 Ağu 2021 |
24İzleyin | CVE-2019-20513İstismar yok | Open edX Ironwood.1 allows support/certificates?user= reflected XSS.edx · open edx · CWE-79 | Orta6,1 | — | %0,5 | 19 Mar 2020 |
23İzleyin | CVE-2015-6671İstismar yok | Open edX edx-platform before 2015-08-25 requires use of the database for storage of SAML SSO secrets, which makes it easier for context-depeedx · edx-platform · CWE-200 | Orta5,9 | — | %0,9 | 13 Mar 2017 |
21İzleyin | CVE-2016-10765İstismar yok | edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address.edx · edx-platform · CWE-20 | Orta5,3 | — | %0,8 | 29 Tem 2019 |
21İzleyin | CVE-2020-13145İstismar yok | Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen.edx · open edx platform · CWE-79 | Orta5,4 | — | %0,5 | 18 May 2020 |
21İzleyin | CVE-2015-6253İstismar yok | edx-platform before 2015-08-17 allows XSS in the Studio listing of courses.edx · edx-platform · CWE-79 | Orta5,4 | — | %0,5 | 29 Tem 2019 |
- CVE-2020-1314438İzleyin
Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New uni
YüksekCVSS 8,8Kavram kanıtıEPSS %11edx · open edx platform18 May 2020
- CVE-2015-560135İzleyin
edx-platform before 2015-07-20 allows code execution by privileged users because the course import endpoint mishandles .tar.gz files.
YüksekCVSS 8,8İstismar yokEPSS %1edx · edx-platform29 Tem 2019
- CVE-2020-1314635İzleyin
Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a formula that is expo
YüksekCVSS 8,8İstismar yokEPSS %1edx · open edx platform18 May 2020
- CVE-2016-1076635İzleyin
edx-platform before 2016-06-06 allows CSRF.
YüksekCVSS 8,8İstismar yokEPSS %1edx · edx-platform29 Tem 2019
- CVE-2024-2220935İzleyin
XBlock custom auth does not respect JWT Scopes
YüksekCVSS 8,8İstismar yokEPSS %1edx · edx-platform13 Oca 2024
- CVE-2015-218630İzleyin
The Ansible edxapp role in the Configuration Repo in edX allows remote websites to spoof edX accounts by leveraging use of the string litera
YüksekCVSS 7,5İstismar yokEPSS %1edx · configuration3 Şub 2018
- CVE-2017-1838030İzleyin
edx-platform before 2017-08-03 allows attackers to trigger password-reset e-mail messages in which the reset link has an attacker-controlled
YüksekCVSS 7,5İstismar yokEPSS %1edx · edx-platform30 Tem 2019
- CVE-2017-1838128İzleyin
The installation process in Open edX before 2017-01-10 exposes a MongoDB instance to external connections with default credentials.
YüksekCVSS 7,2İstismar yokEPSS %1edx · edx-platform30 Tem 2019
- CVE-2015-228627İzleyin
lms/templates/footer-edx-new.html in Open edX edx-platform before 2015-01-29 does not properly restrict links on the password-reset page, wh
OrtaCVSS 6,5İstismar yokEPSS %2edx · open edx19 Mar 2016
- CVE-2022-3219525İzleyin
Open edX platform before 2022-06-06 allows XSS via the "next" parameter in the logout URL.
OrtaCVSS 6,1Kavram kanıtıEPSS %2edx · open edx9 Haz 2022
- CVE-2018-2085924İzleyin
edx-platform before 2018-07-18 allows XSS via a response to a Chemical Equation advanced problem.
OrtaCVSS 6,1İstismar yokEPSS %1edx · edx-platform30 Tem 2019
- CVE-2018-2085824İzleyin
Recommender before 2018-07-18 allows XSS.
OrtaCVSS 6,1İstismar yokEPSS %1edx · recommender9 Ağu 2019
- CVE-2015-696024İzleyin
edx-platform before 2015-09-17 allows XSS via a team name.
OrtaCVSS 6,1İstismar yokEPSS %1edx · edx-platform29 Tem 2019
- CVE-2021-3924824İzleyin
Open edX through Lilac.1 allows XSS in common/static/common/js/discussion/utils.js via crafted LaTeX content within a discussion.
OrtaCVSS 6,1İstismar yokEPSS %1edx · edx-platform17 Ağu 2021
- CVE-2019-2051324İzleyin
Open edX Ironwood.1 allows support/certificates?user= reflected XSS.
OrtaCVSS 6,1İstismar yokEPSS %0edx · open edx19 Mar 2020
- CVE-2015-667123İzleyin
Open edX edx-platform before 2015-08-25 requires use of the database for storage of SAML SSO secrets, which makes it easier for context-depe
OrtaCVSS 5,9İstismar yokEPSS %1edx · edx-platform13 Mar 2017
- CVE-2016-1076521İzleyin
edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address.
OrtaCVSS 5,3İstismar yokEPSS %1edx · edx-platform29 Tem 2019
- CVE-2020-1314521İzleyin
Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen.
OrtaCVSS 5,4İstismar yokEPSS %1edx · open edx platform18 May 2020
- CVE-2015-625321İzleyin
edx-platform before 2015-08-17 allows XSS in the Studio listing of courses.
OrtaCVSS 5,4İstismar yokEPSS %1edx · edx-platform29 Tem 2019