Threats Tagged 'cve-2025-68270'
View all threats tagged with 'cve-2025-68270'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-68270'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2025-68270 is a critical missing authorization vulnerability in the Open edX edx-platform that allows users with CourseLimitedStaffRole assigned at the organization level to access and edit courses in the studio interface improperly. This flaw permits unauthorized course listing and editing, violating intended access controls. The vulnerability affects versions prior to commit 05d0d0936daf82c476617257aa6c35f0cd4ca060, which contains the fix. Exploitation requires low privileges but no user interaction, and it can lead to full confidentiality and integrity compromise of course content with limited availability impact. No known exploits are reported in the wild yet. European educational institutions and organizations using Open edX are at risk, especially those with broad role assignments at the organizational level. Immediate patching and role assignment audits are recommended to mitigate this threat. Join the discussion | CVE Database V5 | 12/16/2025, 18:26:31 UTC Added: 12/16/2025, 19:09:15 UTC |
Showing 1 to 1 of 1 result