CVE-2022-32195: XSS
Published Jun 9, 2022
·Updated
Open edX platform before 2022-06-06 allows XSS via the "next" parameter in the logout URL.
Affected Software
1 affected component
edx Open edX<2022-06-06
Remediation
Event History
Jun 9, 2022
CVE Published
via MITRE·12:36 AM
Data Sourced
via MITRE·12:36 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-32195?
CVE-2022-32195 is considered a medium severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2022-32195?
To fix CVE-2022-32195, you should upgrade your Open edX platform to version 2022-06-06 or later.
3
What platforms are affected by CVE-2022-32195?
CVE-2022-32195 affects Open edX platforms prior to version 2022-06-06.
4
What types of attacks can CVE-2022-32195 facilitate?
CVE-2022-32195 can facilitate cross-site scripting (XSS) attacks via the "next" parameter in the logout URL.
5
Who should be concerned about CVE-2022-32195?
Administrators and users of the Open edX platform should be concerned about CVE-2022-32195, especially if running versions before 2022-06-06.