discuss.openedx.org
https://discuss.openedx.org/t/security-patch-for-logout-page-xss-vulnerability/7408 CVE-2022-32195
MEDIUMNuclei
Open edX <2022-06-06 - Cross-Site Scripting
Record summary
CVE-2022-32195 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Open edX platform before 2022-06-06 allows XSS via the "next" parameter in the logout URL.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMOpen edX <2022-06-06 - Cross-Site ScriptingCVSS 6.1
Open edX before 2022-06-06 contains a reflected cross-site scripting vulnerability via the 'next' parameter in the logout URL.
Impact
Allows attackers to inject malicious scripts into web pages viewed by users, leading to potential data theft or unauthorized actions.
Remediation
Apply the latest security patches or updates provided by Open edX to fix the Cross-Site Scripting vulnerability.
WeaknessesCWE-79
Authorsarafatansari
Template tagscvecve2022openedxxssedxvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:edx:open_edx:*:*:*:*:*:*:*:*
Shodan: http.html:"Open edX"
Shodan: http.html:"open edx"
FOFA: body="open edx"
https://discuss.openedx.org/t/security-patch-for-logout-page-xss-vulnerability/7408 https://github.com/edx https://nvd.nist.gov/vuln/detail/CVE-2022-32195 https://github.com/ARPSyndicate/cvemon https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
3github.com
https://github.com/edx nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-32195