First published: Mon May 18 2020(Updated: )
Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen. These files can contain JavaScript code and thus lead to Stored XSS.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Open edX | =2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13145 has a severity rating that allows for stored cross-site scripting (XSS) attacks, which can be critical based on the context of exploitation.
To mitigate CVE-2020-13145, ensure that your Open edX platform is updated to a version that restricts SVG uploads or properly sanitizes uploaded files.
CVE-2020-13145 allows attackers to upload malicious SVG files that can execute JavaScript, potentially leading to data theft or session hijacking.
If you are using Open edX version 2.5, your software is affected by CVE-2020-13145 and should be addressed promptly.
CVE-2020-13145 was disclosed by security researchers focusing on vulnerabilities within the Open edX platform.