CVE-2017-18380: Edx Edx-Platform

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

edx-platform before 2017-08-03 allows attackers to trigger password-reset e-mail messages in which the reset link has an attacker-controlled domain name.

Affected products

  • Edx Edx-Platform: before 2017-08-03 (fixed in 2017-08-03)

Published 2019-07-30. Last modified 2026-06-17.