Open edX 平台支持以任意规模进行在线学习的创建与交付。在提交 之前,Open edX LMS 平台中的 LTI(学习工具互操作性)Provider 实现中存在一个安全漏洞。位于 中的 函数未对 OAuth nonce 或时间戳进行验证,导致攻击者在捕获一个有效的 LTI 启动请求后,可以将其无限次重放而不会被检测到。该问题已通过提交 修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| openedx | openedx-platform | < 3a5ac856c79557c5c74d8b3e6578f289d7cceecd | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53635 | 7.6 HIGH | Open edX Platform: Insufficient Permission on set_course_mode_price() |
| CVE-2026-55421 | 6.8 MEDIUM | Open edX Platform: SSRF in Studio Video Download Endpoint |
No comments yet