Vulnerabilities
Vulnerable Software
Edx:  >> Edx-Platform  Security Vulnerabilities
The Ansible edxapp role in the Configuration Repo in edX allows remote websites to spoof edX accounts by leveraging use of the string literal "False" instead of a boolean False for the CORS_ORIGIN_ALLOW_ALL setting. Note: this vulnerability was fixed on 2015-03-06, but the version number was not changed.
CVSS Score
7.5
EPSS Score
0.002
Published
2018-02-03
Open edX edx-platform before 2015-08-25 requires use of the database for storage of SAML SSO secrets, which makes it easier for context-dependent attackers to obtain sensitive information by leveraging access to a database backup.
CVSS Score
5.9
EPSS Score
0.003
Published
2017-03-13


Contact Us

Shodan ® - All rights reserved