Логотип exploitDog
bind:CVE-2020-13144
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-13144

Количество 2

Количество 2

nvd логотип

CVE-2020-13144

больше 5 лет назад

Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New unit>Add new component>Problem button>Advanced tab>Custom Python evaluated code" screen, edit the problem, and execute Python code. This leads to arbitrary code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-hc63-fv38-p9mv

больше 3 лет назад

Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New unit>Add new component>Problem button>Advanced tab>Custom Python evaluated code" screen, edit the problem, and execute Python code. This leads to arbitrary code execution.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-13144

Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New unit>Add new component>Problem button>Advanced tab>Custom Python evaluated code" screen, edit the problem, and execute Python code. This leads to arbitrary code execution.

CVSS3: 8.8
4%
Низкий
больше 5 лет назад
github логотип
GHSA-hc63-fv38-p9mv

Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New unit>Add new component>Problem button>Advanced tab>Custom Python evaluated code" screen, edit the problem, and execute Python code. This leads to arbitrary code execution.

CVSS3: 8.8
4%
Низкий
больше 3 лет назад

Уязвимостей на страницу