Lucene search

K
prionPRIOn knowledge basePRION:CVE-2020-13144
HistoryMay 18, 2020 - 7:15 p.m.

Code injection

2020-05-1819:15:00
PRIOn knowledge base
www.prio-n.com
2

8.9 High

AI Score

Confidence

High

0.034 Low

EPSS

Percentile

91.5%

Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the “Create New course>New section>New subsection>New unit>Add new component>Problem button>Advanced tab>Custom Python evaluated code” screen, edit the problem, and execute Python code. This leads to arbitrary code execution.

CPENameOperatorVersion
open_edx_platformeq2.5

8.9 High

AI Score

Confidence

High

0.034 Low

EPSS

Percentile

91.5%