PT-2020-13352 · Edx · Open Edx
Published
2020-05-18
·
Updated
2020-05-20
·
CVE-2020-13145
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Open edX Ironwood version 2.5
Description
The issue allows users to upload SVG files via the "Content>File Uploads" screen, which can contain JavaScript code, leading to Stored XSS.
Recommendations
For Open edX Ironwood version 2.5, consider disabling the file upload feature for SVG files until a patch is available to prevent Stored XSS attacks. Restrict access to the "Content>File Uploads" screen to minimize the risk of exploitation. Avoid using the file upload feature for SVG files in the affected version until the issue is resolved.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Open Edx