CVE-2020-13144
Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New unit>Add new component>Problem button>Advanced tab>Custom Python evaluated code" screen, edit the problem, and execute Python code. This leads to arbitrary code execution.
- Affected products
- Open Edx
- Edx Open Edx Platform
- = 2.5
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 11.0% (96th percentile)
- Weakness
- CWE-94, CWE-862
- NVD status
- Modified
- Published
- 2020-05-18
CVE-2020-13144 at NVD
4 known exploits for CVE-2020-13144
Proof-of-concept code and exploit modules indexed by Sploitus