Show filters
29 Total Results
Displaying 21-29 of 29
Sort by:
Attacker Value
Unknown

CVE-2016-10765

Disclosure Date: July 29, 2019 (last updated November 27, 2024)
edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address.
Attacker Value
Unknown

CVE-2016-10766

Disclosure Date: July 29, 2019 (last updated November 27, 2024)
edx-platform before 2016-06-06 allows CSRF.
Attacker Value
Unknown

CVE-2015-6960

Disclosure Date: July 29, 2019 (last updated November 27, 2024)
edx-platform before 2015-09-17 allows XSS via a team name.
Attacker Value
Unknown

CVE-2015-6253

Disclosure Date: July 29, 2019 (last updated November 27, 2024)
edx-platform before 2015-08-17 allows XSS in the Studio listing of courses.
0
Attacker Value
Unknown

CVE-2015-5601

Disclosure Date: July 29, 2019 (last updated November 27, 2024)
edx-platform before 2015-07-20 allows code execution by privileged users because the course import endpoint mishandles .tar.gz files.
0
Attacker Value
Unknown

CVE-2015-2186

Disclosure Date: February 03, 2018 (last updated November 26, 2024)
The Ansible edxapp role in the Configuration Repo in edX allows remote websites to spoof edX accounts by leveraging use of the string literal "False" instead of a boolean False for the CORS_ORIGIN_ALLOW_ALL setting. Note: this vulnerability was fixed on 2015-03-06, but the version number was not changed.
0
Attacker Value
Unknown

CVE-2015-6671

Disclosure Date: March 13, 2017 (last updated November 26, 2024)
Open edX edx-platform before 2015-08-25 requires use of the database for storage of SAML SSO secrets, which makes it easier for context-dependent attackers to obtain sensitive information by leveraging access to a database backup.
Attacker Value
Unknown

CVE-2015-2286

Disclosure Date: March 19, 2016 (last updated November 25, 2024)
lms/templates/footer-edx-new.html in Open edX edx-platform before 2015-01-29 does not properly restrict links on the password-reset page, which allows user-assisted remote attackers to discover password-reset tokens by reading a referer log after a victim navigates from this page to a social-sharing site.
0
Attacker Value
Unknown

CVE-2001-1538

Disclosure Date: December 31, 2001 (last updated February 22, 2025)
SpeedXess HA-120 DSL router has a default administrative password of "speedxess", which allows remote attackers to gain access.
0