CVE-2015-5601: Malicious File Upload
Published Jul 29, 2019
·Updated
edx-platform before 2015-07-20 allows code execution by privileged users because the course import endpoint mishandles .tar.gz files.
Affected Software
1 affected component
edx edx-platform<2015-07-20
Remediation
Patch Available
Event History
Jul 29, 2019
CVE Published
via MITRE·03:41 PM
Data Sourced
via MITRE·03:41 PM
Description
Frequently Asked Questions
1
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2015-5601.
2
What is the severity level of CVE-2015-5601?
The severity of CVE-2015-5601 is rated as high with a CVSS score of 8.8.
3
How does edx-platform before 2015-07-20 allow code execution by privileged users?
Edx-platform before 2015-07-20 allows code execution by privileged users due to mishandling of .tar.gz files at the course import endpoint.
4
What software is affected by CVE-2015-5601?
The software affected by CVE-2015-5601 is edX edx-platform versions prior to 2015-07-20.
5
Where can I find more information about CVE-2015-5601?
You can find more information about CVE-2015-5601 at https://open.edx.org/announcements/CVE-2015-5601.