Записи edx
19 опубликованных записей вендора edx.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 5,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-20 Improper Input Validation2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-284 Improper Access Control2
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
19 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
38Наблюдать | CVE-2020-13144Proof of concept | Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New uniedx · open edx platform · CWE-94 | Высокая8,8 | — | 11,0 % | 18 мая 2020 г. |
35Наблюдать | CVE-2015-5601Эксплойта нет | edx-platform before 2015-07-20 allows code execution by privileged users because the course import endpoint mishandles .tar.gz files.edx · edx-platform · CWE-434 | Высокая8,8 | — | 1,5 % | 29 июл. 2019 г. |
35Наблюдать | CVE-2020-13146Эксплойта нет | Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a formula that is expoedx · open edx platform · CWE-1236 | Высокая8,8 | — | 1,1 % | 18 мая 2020 г. |
35Наблюдать | CVE-2016-10766Эксплойта нет | edx-platform before 2016-06-06 allows CSRF.edx · edx-platform · CWE-352 | Высокая8,8 | — | 0,6 % | 29 июл. 2019 г. |
35Наблюдать | CVE-2024-22209Эксплойта нет | XBlock custom auth does not respect JWT Scopesedx · edx-platform · CWE-284 | Высокая8,8 | — | 0,6 % | 13 янв. 2024 г. |
30Наблюдать | CVE-2015-2186Эксплойта нет | The Ansible edxapp role in the Configuration Repo in edX allows remote websites to spoof edX accounts by leveraging use of the string literaedx · configuration · CWE-20 | Высокая7,5 | — | 1,1 % | 3 февр. 2018 г. |
30Наблюдать | CVE-2017-18380Эксплойта нет | edx-platform before 2017-08-03 allows attackers to trigger password-reset e-mail messages in which the reset link has an attacker-controllededx · edx-platform · CWE-284 | Высокая7,5 | — | 1,1 % | 30 июл. 2019 г. |
28Наблюдать | CVE-2017-18381Эксплойта нет | The installation process in Open edX before 2017-01-10 exposes a MongoDB instance to external connections with default credentials.edx · edx-platform | Высокая7,2 | — | 1,2 % | 30 июл. 2019 г. |
27Наблюдать | CVE-2015-2286Эксплойта нет | lms/templates/footer-edx-new.html in Open edX edx-platform before 2015-01-29 does not properly restrict links on the password-reset page, whedx · open edx · CWE-200 | Средняя6,5 | — | 2,0 % | 19 мар. 2016 г. |
25Наблюдать | CVE-2022-32195Proof of concept | Open edX platform before 2022-06-06 allows XSS via the "next" parameter in the logout URL.edx · open edx · CWE-79 | Средняя6,1 | — | 2,4 % | 9 июн. 2022 г. |
24Наблюдать | CVE-2018-20859Эксплойта нет | edx-platform before 2018-07-18 allows XSS via a response to a Chemical Equation advanced problem.edx · edx-platform · CWE-79 | Средняя6,1 | — | 1,2 % | 30 июл. 2019 г. |
24Наблюдать | CVE-2018-20858Эксплойта нет | Recommender before 2018-07-18 allows XSS.edx · recommender · CWE-79 | Средняя6,1 | — | 0,9 % | 9 авг. 2019 г. |
24Наблюдать | CVE-2015-6960Эксплойта нет | edx-platform before 2015-09-17 allows XSS via a team name.edx · edx-platform · CWE-79 | Средняя6,1 | — | 0,6 % | 29 июл. 2019 г. |
24Наблюдать | CVE-2021-39248Эксплойта нет | Open edX through Lilac.1 allows XSS in common/static/common/js/discussion/utils.js via crafted LaTeX content within a discussion.edx · edx-platform · CWE-79 | Средняя6,1 | — | 0,6 % | 17 авг. 2021 г. |
24Наблюдать | CVE-2019-20513Эксплойта нет | Open edX Ironwood.1 allows support/certificates?user= reflected XSS.edx · open edx · CWE-79 | Средняя6,1 | — | 0,5 % | 19 мар. 2020 г. |
23Наблюдать | CVE-2015-6671Эксплойта нет | Open edX edx-platform before 2015-08-25 requires use of the database for storage of SAML SSO secrets, which makes it easier for context-depeedx · edx-platform · CWE-200 | Средняя5,9 | — | 0,9 % | 13 мар. 2017 г. |
21Наблюдать | CVE-2016-10765Эксплойта нет | edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address.edx · edx-platform · CWE-20 | Средняя5,3 | — | 0,8 % | 29 июл. 2019 г. |
21Наблюдать | CVE-2020-13145Эксплойта нет | Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen.edx · open edx platform · CWE-79 | Средняя5,4 | — | 0,5 % | 18 мая 2020 г. |
21Наблюдать | CVE-2015-6253Эксплойта нет | edx-platform before 2015-08-17 allows XSS in the Studio listing of courses.edx · edx-platform · CWE-79 | Средняя5,4 | — | 0,5 % | 29 июл. 2019 г. |
- CVE-2020-1314438Наблюдать
Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New uni
ВысокаяCVSS 8,8Proof of conceptEPSS 11 %edx · open edx platform18 мая 2020 г.
- CVE-2015-560135Наблюдать
edx-platform before 2015-07-20 allows code execution by privileged users because the course import endpoint mishandles .tar.gz files.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %edx · edx-platform29 июл. 2019 г.
- CVE-2020-1314635Наблюдать
Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a formula that is expo
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %edx · open edx platform18 мая 2020 г.
- CVE-2016-1076635Наблюдать
edx-platform before 2016-06-06 allows CSRF.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %edx · edx-platform29 июл. 2019 г.
- CVE-2024-2220935Наблюдать
XBlock custom auth does not respect JWT Scopes
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %edx · edx-platform13 янв. 2024 г.
- CVE-2015-218630Наблюдать
The Ansible edxapp role in the Configuration Repo in edX allows remote websites to spoof edX accounts by leveraging use of the string litera
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %edx · configuration3 февр. 2018 г.
- CVE-2017-1838030Наблюдать
edx-platform before 2017-08-03 allows attackers to trigger password-reset e-mail messages in which the reset link has an attacker-controlled
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %edx · edx-platform30 июл. 2019 г.
- CVE-2017-1838128Наблюдать
The installation process in Open edX before 2017-01-10 exposes a MongoDB instance to external connections with default credentials.
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %edx · edx-platform30 июл. 2019 г.
- CVE-2015-228627Наблюдать
lms/templates/footer-edx-new.html in Open edX edx-platform before 2015-01-29 does not properly restrict links on the password-reset page, wh
СредняяCVSS 6,5Эксплойта нетEPSS 2 %edx · open edx19 мар. 2016 г.
- CVE-2022-3219525Наблюдать
Open edX platform before 2022-06-06 allows XSS via the "next" parameter in the logout URL.
СредняяCVSS 6,1Proof of conceptEPSS 2 %edx · open edx9 июн. 2022 г.
- CVE-2018-2085924Наблюдать
edx-platform before 2018-07-18 allows XSS via a response to a Chemical Equation advanced problem.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %edx · edx-platform30 июл. 2019 г.
- CVE-2018-2085824Наблюдать
Recommender before 2018-07-18 allows XSS.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %edx · recommender9 авг. 2019 г.
- CVE-2015-696024Наблюдать
edx-platform before 2015-09-17 allows XSS via a team name.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %edx · edx-platform29 июл. 2019 г.
- CVE-2021-3924824Наблюдать
Open edX through Lilac.1 allows XSS in common/static/common/js/discussion/utils.js via crafted LaTeX content within a discussion.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %edx · edx-platform17 авг. 2021 г.
- CVE-2019-2051324Наблюдать
Open edX Ironwood.1 allows support/certificates?user= reflected XSS.
СредняяCVSS 6,1Эксплойта нетEPSS 0 %edx · open edx19 мар. 2020 г.
- CVE-2015-667123Наблюдать
Open edX edx-platform before 2015-08-25 requires use of the database for storage of SAML SSO secrets, which makes it easier for context-depe
СредняяCVSS 5,9Эксплойта нетEPSS 1 %edx · edx-platform13 мар. 2017 г.
- CVE-2016-1076521Наблюдать
edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %edx · edx-platform29 июл. 2019 г.
- CVE-2020-1314521Наблюдать
Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %edx · open edx platform18 мая 2020 г.
- CVE-2015-625321Наблюдать
edx-platform before 2015-08-17 allows XSS in the Studio listing of courses.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %edx · edx-platform29 июл. 2019 г.