← Back to CVE List

CVE-2020-13145

Published: 2020-05-18T19:15Z
Last Modified: 2024-11-21T05:00Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen. These files can contain JavaScript code and thus lead to Stored XSS. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt