PT-2014-4478 · Ilias Open Source E Learning Platform · Ilias
Publicado
2014-03-02
·
Atualizado
2014-03-03
·
CVE-2014-2090
CVSS v2.0
3.5
Baixa
| Vetor | AV:N/AC:M/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
ILIAS version 4.4.1
Description
The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote authenticated users to inject arbitrary web script or HTML. The vulnerable parameters are
tar, tar val, and title.Recommendations
For ILIAS version 4.4.1, update to a version that contains a fix for this issue to prevent exploitation. As a temporary workaround, consider restricting access to the
ilias.php file or avoiding the use of the tar, tar val, and title parameters until a patch is available.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ilias