CVE-2019-20513: XSS
Published Mar 19, 2020
·Updated
Open edX Ironwood.1 allows support/certificates?user= reflected XSS.
Affected Software
1 affected component
edx Open edX=2019-03-15
Event History
Mar 19, 2020
CVE Published
via MITRE·05:35 PM
Data Sourced
via MITRE·05:35 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20513?
CVE-2019-20513 has been rated as a medium severity vulnerability due to its potential exploitation via reflected cross-site scripting.
2
How do I fix CVE-2019-20513?
To fix CVE-2019-20513, you should upgrade to a patched version of Open edX that addresses the reflected XSS vulnerability.
3
What impact does CVE-2019-20513 have on users of Open edX?
CVE-2019-20513 can allow attackers to execute arbitrary scripts in the context of users, potentially leading to data theft or session hijacking.
4
Is CVE-2019-20513 present in the latest version of Open edX?
CVE-2019-20513 is present in Open edX Ironwood.1 and should be tested for in subsequent versions to ensure it is patched.
5
How can I determine if my installation of Open edX is vulnerable to CVE-2019-20513?
You can determine vulnerability by checking if your installation version is 2019-03-15 and testing for reflected XSS using appropriate security tools.