Description
Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen. These files can contain JavaScript code and thus lead to Stored XSS.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-5421 | Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen. These files can contain JavaScript code and thus lead to Stored XSS. |
References
| Link | Providers |
|---|---|
| https://stark0de.com/2020/05/17/openedx-vulnerabilities.html |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T12:11:19.043Z
Reserved: 2020-05-18T00:00:00.000Z
Link: CVE-2020-13145
No data.
Status : Modified
Published: 2020-05-18T19:15:11.543
Modified: 2024-11-21T05:00:44.520
Link: CVE-2020-13145
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD