PT-2014-4478 · Ilias Open Source E Learning Platform · Ilias
Published
2014-03-02
·
Updated
2014-03-03
·
CVE-2014-2090
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
ILIAS version 4.4.1
Description
The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote authenticated users to inject arbitrary web script or HTML. The vulnerable parameters are
tar, tar val, and title.Recommendations
For ILIAS version 4.4.1, update to a version that contains a fix for this issue to prevent exploitation. As a temporary workaround, consider restricting access to the
ilias.php file or avoiding the use of the tar, tar val, and title parameters until a patch is available.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ilias