CVE-2018-20859: XSS
Published Jul 30, 2019
·Updated
edx-platform before 2018-07-18 allows XSS via a response to a Chemical Equation advanced problem.
Affected Software
1 affected component
edx edx-platform<2018-07-18
Remediation
Event History
Jul 30, 2019
CVE Published
via MITRE·06:46 PM
Data Sourced
via MITRE·06:46 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20859?
CVE-2018-20859 has a medium severity rating as it allows for cross-site scripting (XSS) vulnerabilities.
2
How do I fix CVE-2018-20859?
To fix CVE-2018-20859, update the edx-platform to a version later than 2018-07-18.
3
What type of vulnerability is CVE-2018-20859?
CVE-2018-20859 is classified as a cross-site scripting (XSS) vulnerability.
4
What software versions are affected by CVE-2018-20859?
CVE-2018-20859 affects edx-platform versions prior to 2018-07-18.
5
Can CVE-2018-20859 be exploited in a production environment?
Yes, CVE-2018-20859 can be exploited in production environments if proper precautions are not taken.