Open edX 平台支持以任意规模进行在线学习的创建与交付。在提交 59bb6d6 之前,位于 第 430 行的视图函数 仅被 装饰器保护,且未执行任何课程级别的权限检查。任何已认证用户——包括没有任何课程角色的学习者账户——都可以通过发送单个 POST 请求来覆盖平台上任意课程的荣誉模式(honor mode)价格及货币。配套的前端模态框已在之前的清理工作中被移除,但 URL 路由和视图函数仍保持活跃,这使得该端点成为一个缺少保护的“孤儿”端点。该问题已通过提交 59bb6d6 修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| openedx | openedx-platform | < 59bb6d669e4fdc24d96afb809e12119372d9e257 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55421 | 6.8 MEDIUM | Open edX Platform: SSRF in Studio Video Download Endpoint |
| CVE-2026-53636 | 4.7 MEDIUM | Open edX LTI OAuth Replay Attack |
No comments yet