CVE-2015-6960: XSS
Published Jul 29, 2019
·Updated
edx-platform before 2015-09-17 allows XSS via a team name.
Affected Software
1 affected component
edx edx-platform<2015-09-17
Remediation
Patch Available
Event History
Jul 29, 2019
CVE Published
via MITRE·03:30 PM
Data Sourced
via MITRE·03:30 PM
Description
Frequently Asked Questions
1
What is CVE-2015-6960?
CVE-2015-6960 is a vulnerability that allows cross-site scripting (XSS) attacks via a team name in edx-platform before 2015-09-17.
2
What is the severity of CVE-2015-6960?
The severity of CVE-2015-6960 is medium with a CVSS score of 6.1.
3
How does CVE-2015-6960 affect edx-platform?
CVE-2015-6960 affects edx-platform versions before 2015-09-17 by allowing XSS attacks through a team name.
4
How can I fix CVE-2015-6960?
To fix CVE-2015-6960, update your edx-platform installation to version 2015-09-17 or later.
5
Where can I find more information about CVE-2015-6960?
You can find more information about CVE-2015-6960 at the following link: [CVE-2015-6960](https://open.edx.org/announcements/cve-2015-6960/)