CVE-2020-13144: Code Injection
Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New unit>Add new component>Problem button>Advanced tab>Custom Python evaluated code" screen, edit the problem, and execute Python code. This leads to arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-13144?
CVE-2020-13144 is classified as a high-severity vulnerability due to its exploitation potential for remote code execution.
How do I fix CVE-2020-13144?
To fix CVE-2020-13144, ensure that CodeJail is used when creating problems in the Open edX platform.
Who is affected by CVE-2020-13144?
CVE-2020-13144 affects any installation of Open edX Ironwood 2.5 where CodeJail is not enabled.
What type of attack does CVE-2020-13144 enable?
CVE-2020-13144 allows for arbitrary code execution, which can lead to malicious actions on the server.
Can CVE-2020-13144 be exploited without authentication?
Yes, CVE-2020-13144 can be exploited by authenticated users with access to the course creation interface.