CVE 9.9 CRITICAL

CourseLimitedStaff Role Allows Studio Access_CVE-2025-68270

9.9 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L

Description

The Open edX Platform is a learning management platform. Prior to commit 05d0d0936daf82c476617257aa6c35f0cd4ca060, CourseLimitedStaffRole users are able to access and edit courses in studio if they are granted the role on an org rather than on a course, and CourseLimitedStaffRole users are able to list courses they have the role on in studio even though they are not meant to have any access on the studio side for the course. Commit 05d0d0936daf82c476617257aa6c35f0cd4ca060 fixes the issue.

AI Analysis

CourseLimitedStaffRole users can access and edit courses in studio if granted the role on an org rather than on a course, despite not being meant to have access.

Basic Information

ID CVE-2025-68270
Source GitHub_M
Published Dec 16, 2025 at 18:26

Affected Product

Vendor openedx
Product edx-platform
Version < 05d0d0936daf82c476617257aa6c35f0cd4ca060
Affected Versions openedx edx-platform < 05d0d0936daf82c476617257aa6c35f0cd4ca060

CWE Classification

AI Assessment

AI Score 9.9 / 10
AI Severity Critical
Vendor Open edX
Product edx-platform
Version < 05d0d0936daf82c476617257aa6c35f0cd4ca060

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.