Record summary

CVE-2022-32195 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Open edX platform before 2022-06-06 allows XSS via the "next" parameter in the logout URL.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMOpen edX <2022-06-06 - Cross-Site ScriptingCVSS 6.1

Open edX before 2022-06-06 contains a reflected cross-site scripting vulnerability via the 'next' parameter in the logout URL.

Impact

Allows attackers to inject malicious scripts into web pages viewed by users, leading to potential data theft or unauthorized actions.

Remediation

Apply the latest security patches or updates provided by Open edX to fix the Cross-Site Scripting vulnerability.

WeaknessesCWE-79
Authorsarafatansari
Template tagscvecve2022openedxxssedxvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:edx:open_edx:*:*:*:*:*:*:*:*
Shodan: http.html:"Open edX"
Shodan: http.html:"open edx"
FOFA: body="open edx"

Source: ProjectDiscovery

References

3