Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Stark0De

#29604of 53,624
8.8Total CVSS
Vulnerabilities · 1
PT-2020-13353
8.8
2020-05-18
Edx · Open Edx Studio · CVE-2020-13146
**Name of the Vulnerable Software and Affected Versions** Open edX Studio version 2.5 **Description** The issue allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a formula that is exported via the "Course>Data Downloads>Reports>Download profile info" feature. **Recommendations** For Open edX Studio version 2.5, consider restricting access to the "Course>Data Downloads>Reports>Download profile info" feature until a patch is available to prevent potential CSV injection attacks. Additionally, avoid adding cohorts with formulas in the Course>Instructor>Cohorts section to minimize the risk of exploitation.