Back to overview

CVE-2025-68270

CRITICAL
9.9
CVSS 3.1
Description
The Open edX Platform is a learning management platform. Prior to commit 05d0d0936daf82c476617257aa6c35f0cd4ca060, CourseLimitedStaffRole users are able to access and edit courses in studio if they are granted the role on an org rather than on a course, and CourseLimitedStaffRole users are able to list courses they have the role on in studio even though they are not meant to have any access on the studio side for the course. Commit 05d0d0936daf82c476617257aa6c35f0cd4ca060 fixes the issue.

Metadata

CVE ID
CVE-2025-68270
State
PUBLISHED
Assigner
GitHub_M
Reserved
2025-12-16 14:05 UTC
Published
2025-12-16 18:26 UTC
Last updated
2025-12-16 19:55 UTC
Primary CWE
CWE-862
CWE-862: Missing Authorization
Vendor / Product
openedx / edx-platform
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
openedx edx-platform < 05d0d0936daf82c476617257aa6c35f0cd4ca060
Weakness (CWE)
CWESourceDescription
CWE-862 cna CWE-862: Missing Authorization
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
References (4)
Back to overview