CVE-2015-2286: Edx Open Edx
Medium severity, CVSS 6.5. EPSS: 2% chance of exploitation in the next 30 days.
lms/templates/footer-edx-new.html in Open edX edx-platform before 2015-01-29 does not properly restrict links on the password-reset page, which allows user-assisted remote attackers to discover password-reset tokens by reading a referer log after a victim navigates from this page to a social-sharing site.
Affected products
- Edx Open Edx: up to and including 2015-01-27
Published 2016-03-19. Last modified 2026-06-17.