CyberRota Analysis
AI analysis pending.
CVE
CVE-2020-13145
Severity
MEDIUM
CVSS
5.4
EPSS
0.53%
Java
Original NVD Description
Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen. These files can contain JavaScript code and thus lead to Stored XSS.
Related CVEs
Other vulnerabilities affecting the same vendor(s)