OpenLearnX Remote Code Execution Vulnerability via Python Sandbox Escape
Vulnerability
A remote code execution vulnerability has been identified in OpenLearnX versions prior to 2.0.3. This issue arises from a sandbox escape in the code execution environment, allowing arbitrary command execution. The vulnerability has been patched in version 2.0.3.
Impact
Exploitation of this vulnerability allows for remote code execution on the server where OpenLearnX is hosted.
Reproduction
The vulnerability can be reproduced by executing code in the OpenLearnX coding environment. The code execution will bypass the sandbox restrictions, allowing for arbitrary commands to be executed on the server.
Remediation
Users can upgrade to OpenLearnX version 2.0.3 to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
