CVE-2017-18380: High severity edx open edx platform vulnerability
edx-platform before 2017-08-03 allows attackers to trigger password-reset e-mail messages in which the reset link has an attacker-controlled domain name.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-18380?
CVE-2017-18380 is classified as a medium severity vulnerability due to its potential to facilitate phishing attacks via malicious password-reset emails.
How do I fix CVE-2017-18380?
To fix CVE-2017-18380, update to edx-platform version 2017-08-03 or later to ensure the password-reset email links are secure.
What impact does CVE-2017-18380 have on users?
CVE-2017-18380 can lead to user credential compromise as attackers could send fake password reset emails with links leading to their own malicious sites.
Is CVE-2017-18380 still a threat if I update my edx-platform software?
No, updating the edx-platform to version 2017-08-03 or later mitigates the threat posed by CVE-2017-18380.
Who is affected by CVE-2017-18380?
CVE-2017-18380 affects anyone using edx-platform versions prior to 2017-08-03.