GHSA-3j5x-7ccf-ppgm
Dashboard / Vulnerabilities / GHSA-3j5x-7ccf-ppgm
GHSA-3j5x-7ccf-ppgm
Summary: Cross-site scripting in recommender-xblock
Details: Recommender before 1.3.1 allows XSS. It is possible for a learner to craft a fake resource to recommender, that includes script which could possibly steal credentials from staff if they are lured into viewing the recommended resource.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-20858, https://github.com/edx/RecommenderXBlock/pull/2, https://github.com/advisories/GHSA-3j5x-7ccf-ppgm, https://github.com/openedx/RecommenderXBlock, https://github.com/pypa/advisory-database/tree/main/vulns/recommender-xblock/PYSEC-2019-219.yaml, https://groups.google.com/forum/#!topic/openedx-announce/SF8Sn6MuUTg
Affected packages
Package
Name: recommender-xblock
Purl: pkg:pypi/recommender-xblock
Affected ranges
Type: ECOSYSTEM
Events:
