PT-2018-4362 · Edx · Edx Configuration Repo

Published

2018-02-03

·

Updated

2018-03-02

·

CVE-2015-2186

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions edx Configuration Repo (affected versions not specified)
Description The issue allows remote websites to spoof edX accounts by leveraging the use of the string literal "False" instead of a boolean False for the CORS ORIGIN ALLOW ALL setting.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-2186

Affected Products

Edx Configuration Repo