CVE-2016-10765: Input Validation
Published Jul 29, 2019
·Updated
edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address.
Affected Software
1 affected component
edx edx-platform<2016-06-10
Remediation
Event History
Jul 29, 2019
CVE Published
via MITRE·04:10 PM
Data Sourced
via MITRE·04:10 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10765?
CVE-2016-10765 has a medium severity rating due to potential unauthorized account activation.
2
How do I fix CVE-2016-10765?
To fix CVE-2016-10765, update edx-platform to version 2016-06-10 or later.
3
What does CVE-2016-10765 allow attackers to do?
CVE-2016-10765 allows attackers to activate user accounts using a spoofed email address.
4
In which versions is CVE-2016-10765 present?
CVE-2016-10765 is present in all versions of edx-platform prior to 2016-06-10.
5
Is there a workaround for CVE-2016-10765 prior to applying the patch?
A viable workaround for CVE-2016-10765 includes disabling email-based account activation until the patch is applied.