First published: Mon Dec 02 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eduNEXT Open edX LMS allows Reflected XSS.This issue affects Open edX LMS: from n/a through 2.6.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Open edX | >=n/a<2.6.1 | |
WordPress Open edX LMS plugin | <=2.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-52452 is classified as a reflected cross-site scripting (XSS) vulnerability affecting certain versions of Open edX LMS.
To fix CVE-2024-52452, update your eduNEXT Open edX LMS to version 2.6.1 or later.
CVE-2024-52452 affects Open edX LMS versions from 'n/a' up to and including 2.6.1.
Yes, CVE-2024-52452 can potentially allow attackers to execute scripts in the context of a user's session, affecting user data.
Yes, the WordPress Open edX LMS plugin versions up to and including 2.6.1 are also vulnerable to CVE-2024-52452.