Report Email Alerts Open Bug Bounty: 119673 coordinated disclosures
Full Disclosure: 32442 vulnerabilities
Total Vulnerabilities Fixed: 38977
125709 vulnerable websites, 13065 VIP websites
3043 security researchers, 4020 notification subscribers

edx.org Security Vulnerability

On the 03.05.2015 security researcher Alyssa_Herrera Twitter: @_Psycho_Mantis
Approved XSS vulnerabilities: 1589
Approved XSS vulnerabilities on VIP websites: 468
disclosed XSS vulnerability affecting edx.org website.

On the 03.05.2015 security researcher Alyssa_Herrera discovered and reported XSS vulnerability affecting edx.org

On our side, we have notified website owner via all reasonable communication channels about the vulnerability, so it can be patched as quickly as possible.

Currently the vulnerability is patched and does not represent any security risk for the website or its visitors.

Vulnerability Details

Open Bug Bounty ID:

OBB-60691

edx.org Description

edX | Free online courses from the world's best universities. EdX offers free online courses and classes. Find the latest MOOC from the world’s best universities including MIT, Harvard, Berkeley, UT and others. Topics include business, computer science, finance, history, literature, math,

Vulnerable URL:

https://www.edx.org/courses?search_query='"></title><script> alert("XSSPOSED")</script>>/

Other details:

Patched:Yes, at 04.05.2015
Latest check for patch:04.05.2015 03:14 GMT
Vulnerability type:XSS
Vulnerability status:Publicly disclosed
Alexa Rank2013
Google Pagerank10
VIP website status:Yes
Check edx.org for malware:Click here
Check edx.org SSL connection:Click here (Grade: A) Refresh Results

Screenshot: edx.org XSS vulnerability

Mirror: Click here to view the mirror


Notification & Disclosure Timeline

3 May, 2015 at 22:58 GMTVulnerability reported
3 May, 2015 at 23:00 GMTVulnerability verified and confirmed

Comments:

Please login via twitter to be the first one to comment.


Latest Vulnerabilities on *.edx.org

Vulnerability Reported by Type Status Reported on
Full Disclosure
patched
03.05.2015

Latest Vulnerabilities Reported by Alyssa_Herrera

Domain Type Status Reported
Open Bug Bounty
On Hold
23.05.2017
Open Bug Bounty
On Hold
22.05.2017
Open Bug Bounty
On Hold
22.05.2017
Open Bug Bounty
On Hold
21.05.2017
Open Bug Bounty
On Hold
15.05.2017
Open Bug Bounty
On Hold
15.05.2017
Open Bug Bounty
On Hold
15.05.2017
Open Bug Bounty
On Hold
06.05.2017
Open Bug Bounty
On Hold
06.05.2017
Open Bug Bounty
On Hold
04.05.2017
Open Bug Bounty
On Hold
02.05.2017
Open Bug Bounty
On Hold
02.05.2017
Open Bug Bounty
On Hold
02.05.2017
Open Bug Bounty
On Hold
01.05.2017
Open Bug Bounty
On Hold
30.04.2017
Open Bug Bounty
On Hold
30.04.2017
Open Bug Bounty
On Hold
30.04.2017
Open Bug Bounty
On Hold
30.04.2017
Open Bug Bounty
On Hold
30.04.2017
Open Bug Bounty
On Hold
30.04.2017

Latest VIP Submissions

protv.md
Reported by OmniGooch Recommendations received: 3
Approved XSS vulnerabilities: 3196
Approved XSS vulnerabilities on VIP websites: 191
on 23.05.2017
unieuro.it
Reported by evaristegal0is Twitter: @evaristegal0is
Recommendations received: 2
Approved XSS vulnerabilities: 134
Approved XSS vulnerabilities on VIP websites: 29
on 23.05.2017
webdeveloper.com
Reported by Random_Robbie Twitter: @Random_Robbie
Recommendations received: 17
Approved XSS vulnerabilities: 4414
Approved XSS vulnerabilities on VIP websites: 492
on 23.05.2017
minecraftmods.com
Reported by Xany Twitter: @Xanyrekt
Approved XSS vulnerabilities: 1055
Approved XSS vulnerabilities on VIP websites: 155
on 23.05.2017
metal-archives.com
Reported by amlnspqr Twitter: @amlnspqr
Recommendations received: 6
Approved XSS vulnerabilities: 1579
Approved XSS vulnerabilities on VIP websites: 265
on 23.05.2017
molex.com
Reported by M0r3h4x Twitter: @berkanexo
Approved XSS vulnerabilities: 155
Approved XSS vulnerabilities on VIP websites: 10
on 23.05.2017
gomplayer.jp
Reported by keritzy Twitter: @keritzy
Approved XSS vulnerabilities: 638
Approved XSS vulnerabilities on VIP websites: 22
on 23.05.2017
acer.com
Reported by keritzy Twitter: @keritzy
Approved XSS vulnerabilities: 638
Approved XSS vulnerabilities on VIP websites: 22
on 23.05.2017
kenyamoja.com
Reported by keritzy Twitter: @keritzy
Approved XSS vulnerabilities: 638
Approved XSS vulnerabilities on VIP websites: 22
on 23.05.2017
ssbcrack.com
Reported by keritzy Twitter: @keritzy
Approved XSS vulnerabilities: 638
Approved XSS vulnerabilities on VIP websites: 22
on 23.05.2017

Latest Submissions

puralopez.com
Reported by OmniGooch Recommendations received: 3
Approved XSS vulnerabilities: 3196
Approved XSS vulnerabilities on VIP websites: 191
on 24.05.2017
softelia.com
Reported by OmniGooch Recommendations received: 3
Approved XSS vulnerabilities: 3196
Approved XSS vulnerabilities on VIP websites: 191
on 24.05.2017
misco.be
Reported by OmniGooch Recommendations received: 3
Approved XSS vulnerabilities: 3196
Approved XSS vulnerabilities on VIP websites: 191
on 24.05.2017
basket.dk
Reported by OmniGooch Recommendations received: 3
Approved XSS vulnerabilities: 3196
Approved XSS vulnerabilities on VIP websites: 191
on 24.05.2017
e9898.com
Reported by OmniGooch Recommendations received: 3
Approved XSS vulnerabilities: 3196
Approved XSS vulnerabilities on VIP websites: 191
on 23.05.2017
kerekpar-lakat.hu
Reported by OmniGooch Recommendations received: 3
Approved XSS vulnerabilities: 3196
Approved XSS vulnerabilities on VIP websites: 191
on 23.05.2017
firmamburda.com
Reported by OmniGooch Recommendations received: 3
Approved XSS vulnerabilities: 3196
Approved XSS vulnerabilities on VIP websites: 191
on 23.05.2017
luger.se
Reported by OmniGooch Recommendations received: 3
Approved XSS vulnerabilities: 3196
Approved XSS vulnerabilities on VIP websites: 191
on 23.05.2017
hayabusafight.com
Reported by ThomySec Approved XSS vulnerabilities: 41
Approved XSS vulnerabilities on VIP websites: 12
on 23.05.2017
niagarafallscomiccon.com
Reported by OmniGooch Recommendations received: 3
Approved XSS vulnerabilities: 3196
Approved XSS vulnerabilities on VIP websites: 191
on 23.05.2017