CVE-2020-13145: XSS
Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen. These files can contain JavaScript code and thus lead to Stored XSS.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-13145?
CVE-2020-13145 has a severity rating that allows for stored cross-site scripting (XSS) attacks, which can be critical based on the context of exploitation.
How do I fix CVE-2020-13145?
To mitigate CVE-2020-13145, ensure that your Open edX platform is updated to a version that restricts SVG uploads or properly sanitizes uploaded files.
What does CVE-2020-13145 allow an attacker to do?
CVE-2020-13145 allows attackers to upload malicious SVG files that can execute JavaScript, potentially leading to data theft or session hijacking.
Is my software affected by CVE-2020-13145?
If you are using Open edX version 2.5, your software is affected by CVE-2020-13145 and should be addressed promptly.
Who discovered CVE-2020-13145?
CVE-2020-13145 was disclosed by security researchers focusing on vulnerabilities within the Open edX platform.