edx-platform before 2017-08-03 allows attackers to trigger password-reset e-mail messages in which the reset link has an attacker-controlled domain name.
References
Link | Resource |
---|---|
https://github.com/edx/edx-platform/pull/15773 | Patch Third Party Advisory |
https://groups.google.com/forum/#%21topic/openedx-announce/QTvijt48bAY |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2019-07-30T12:30:50
Updated: 2019-07-30T12:30:50
Reserved: 2019-07-29T00:00:00
Link: CVE-2017-18380
JSON object: View
NVD Information
Status : Modified
Published: 2019-07-30T13:15:13.310
Modified: 2023-11-07T02:41:54.797
Link: CVE-2017-18380
JSON object: View
Redhat Information
No data.
CWE