CVE-2021-39248: XSS
Published Aug 17, 2021
·Updated
Open edX through Lilac.1 allows XSS in common/static/common/js/discussion/utils.js via crafted LaTeX content within a discussion.
Affected Software
1 affected component
edx edx-platform
Remediation
Patch Available
Event History
Aug 17, 2021
CVE Published
via MITRE·08:33 PM
Data Sourced
via MITRE·08:33 PM
Description
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-39248?
The severity of CVE-2021-39248 is medium with a CVSS score of 6.1.
2
How can I exploit CVE-2021-39248?
CVE-2021-39248 can be exploited by injecting crafted LaTeX content within a discussion on Open edX through Lilac.1.
3
Is there a fix for CVE-2021-39248?
There is no official fix available for CVE-2021-39248 at the moment. It is recommended to stay updated with the vendor's security advisories.