PT-2022-21146 · Open Edx · Open Edx
Published
2022-06-09
·
Updated
2022-06-15
·
CVE-2022-32195
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Open edX platform versions prior to 2022-06-06
Description
The issue allows for XSS via the
next parameter in the logout URL.Recommendations
For versions prior to 2022-06-06, update to a version released after 2022-06-06 to resolve the issue. As a temporary workaround, consider restricting access to the logout URL or avoiding the use of the
next parameter until the issue is resolved.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Open Edx