CVE-2024-33525

May 21, 2024, 7:15 p.m.

Product(s) Impacted

ILIAS

  • 7.20 - 7.30
  • 8.4 - 8.10
  • 9.0

Description

A Stored Cross-site Scripting (XSS) vulnerability in the "Import of organizational units and title of organizational unit" feature in ILIAS 7.20 to 7.30 and ILIAS 8.4 to 8.10 as well as ILIAS 9.0 allows remote authenticated attackers with administrative privileges to inject arbitrary web script or HTML via XML file upload.

Weaknesses

Date

Published: May 21, 2024, 7:15 p.m.

Last Modified: May 21, 2024, 7:15 p.m.

Status : Received

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

cve@mitre.org

References