CVE-2020-13146
18.05.2020, 19:15
Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a formula that is exported via the "Course>Data Downloads>Reports>Download profile info" feature.Enginsight
Vendor | Product | Version |
---|---|---|
edx | open_edx_platform | 2.5 |
𝑥
= Vulnerable software versions