CVE-2020-13145
EUVD-2020-542118.05.2020, 19:15
Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen. These files can contain JavaScript code and thus lead to Stored XSS.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| edx | open_edx_platform | 2.5 |
𝑥
= Vulnerable software versions