Filtered by vendor Edx Subscriptions
Filtered by product Configuration Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2018-25145 2 Edx, Microhardcorp 23 Configuration, Bullet-3g, Bullet-3g Firmware and 20 more 2026-07-28 6.5 Medium
Microhard Systems IPn4G 1.1.0 contains a configuration file disclosure vulnerability that allows authenticated attackers to download sensitive system configuration files. Attackers can retrieve configuration files from multiple directories including '/www', '/etc/m_cli/', and '/tmp' to access system passwords and network settings.
CVE-2015-2186 1 Edx 2 Configuration, Edx-platform 2024-11-21 N/A
The Ansible edxapp role in the Configuration Repo in edX allows remote websites to spoof edX accounts by leveraging use of the string literal "False" instead of a boolean False for the CORS_ORIGIN_ALLOW_ALL setting. Note: this vulnerability was fixed on 2015-03-06, but the version number was not changed.