ID | CVE-2020-13145 | ||||||
Sažetak | Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen. These files can contain JavaScript code and thus lead to Stored XSS. | ||||||
Reference | |||||||
CVSS |
|
||||||
Pristup |
|
||||||
Impact |
|
||||||
CVSS vektor | AV:N/AC:M/Au:S/C:N/I:P/A:N | ||||||
Zadnje važnije ažuriranje | 20-05-2020 - 18:30 | ||||||
Objavljeno | 18-05-2020 - 19:15 |