CVE-2024-43782 is a critical vulnerability affecting Open edX's openedx-translations repository, stemming from insufficient validation of translation files. Prior to a patch, the repository lacked protections against malformed translations and script injections that were present in older validation processes. This allows for unauthenticated remote attackers to achieve full compromise (confidentiality, integrity, availability) with low attack complexity, as indicated by its CVSS score of 9.8. Despite its critical severity, there is currently no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
redwood1CPE matchmatch criteria | cpe:2.3:a:openedx:openedx:redwood1:*:*:*:*:*:*:* | ||
redwood2CPE matchmatch criteria | cpe:2.3:a:openedx:openedx:redwood2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.