Vulnerability Description
lms/templates/footer-edx-new.html in Open edX edx-platform before 2015-01-29 does not properly restrict links on the password-reset page, which allows user-assisted remote attackers to discover password-reset tokens by reading a referer log after a victim navigates from this page to a social-sharing site.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Edx | Open Edx | <= 2015-01-27 |
Related Weaknesses (CWE)
References
- https://github.com/edx/edx-platform/commit/a1ffcc52594b1e7240501aab0ea145f1da3ed
- https://open.edx.org/CVE-2015-2286Vendor Advisory
- https://github.com/edx/edx-platform/commit/a1ffcc52594b1e7240501aab0ea145f1da3ed
- https://open.edx.org/CVE-2015-2286Vendor Advisory
FAQ
What is CVE-2015-2286?
CVE-2015-2286 is a vulnerability with a CVSS score of 6.5 (MEDIUM). lms/templates/footer-edx-new.html in Open edX edx-platform before 2015-01-29 does not properly restrict links on the password-reset page, which allows user-assisted remote attackers to discover passwo...
How severe is CVE-2015-2286?
CVE-2015-2286 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-2286?
Check the references section above for vendor advisories and patch information. Affected products include: Edx Open Edx.