CVE-2015-2286: Infoleak
Published Mar 19, 2016
·Updated
lms/templates/footer-edx-new.html in Open edX edx-platform before 2015-01-29 does not properly restrict links on the password-reset page, which allows user-assisted remote attackers to discover password-reset tokens by reading a referer log after a victim navigates from this page to a social-sharing site.
Affected Software
1 affected component
edx Open edX<=2015-01-27
Event History
Mar 19, 2016
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2286?
CVE-2015-2286 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2015-2286?
To fix CVE-2015-2286, update to a version of Open edX newer than 2015-01-27.
3
What does CVE-2015-2286 affect?
CVE-2015-2286 affects the Open edX platform prior to version 2015-01-29.
4
What is the impact of CVE-2015-2286?
The impact of CVE-2015-2286 allows user-assisted remote attackers to discover password-reset tokens.
5
How can attackers exploit CVE-2015-2286?
Attackers can exploit CVE-2015-2286 by tricking victims into navigating from the password-reset page to a social-sharing link.