CVE-2020-13145
18.05.2020, 19:15
Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen. These files can contain JavaScript code and thus lead to Stored XSS.
Vendor | Product | Version |
---|---|---|
edx | open_edx_platform | 2.5 |
𝑥
= Vulnerable software versions