PT-2020-13352 · Edx · Open Edx

Published

2020-05-18

·

Updated

2020-05-20

·

CVE-2020-13145

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Open edX Ironwood version 2.5
Description The issue allows users to upload SVG files via the "Content>File Uploads" screen, which can contain JavaScript code, leading to Stored XSS.
Recommendations For Open edX Ironwood version 2.5, consider disabling the file upload feature for SVG files until a patch is available to prevent Stored XSS attacks. Restrict access to the "Content>File Uploads" screen to minimize the risk of exploitation. Avoid using the file upload feature for SVG files in the affected version until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-13145

Affected Products

Open Edx