Impact
The vulnerability is a stored CSS injection that occurs when an enrolled student places CSS‑capable markup into a discussion post title. The Open edX Platform’s email digest engine later treats that title as safe HTML, allowing the malicious CSS to be rendered in recipients’ email clients. This can be used to spoof message content, embed tracking pixels or display misleading UI elements, compromising the authenticity of emails and potentially enabling phishing.
Affected Systems
The affected product is the Open edX Platform, specifically the versions that include the add_additional_attributes_to_notifications function before the Ulmo and Verawood.1 releases. Users running Redwood through Ulmo, or older releases prior to the fix, are vulnerable. The issue involves the LMS discussion REST API and the notifications rendering templates.
Risk and Exploitability
The CVSS score is 6.1, indicating moderate severity. EPSS is not available and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that attackers need the ability to create or modify discussion posts to inject malicious CSS. The vulnerability can be exploited without privileged system access, making it a feasible threat for those who can compose or edit discussion titles. Once a hazardous title is stored, email digest rendering will display it as safe HTML, allowing content spoofing or phishing when other learners open the email.
OpenCVE Enrichment