Описание
Stored XSS vulnerability in the Media Objects component of ILIAS before 5.1.21 and 5.2.x before 5.2.9 allows an authenticated user to inject JavaScript to gain administrator privileges, related to the setParameter function in Services/MediaObjects/classes/class.ilMediaItem.php.
Ссылки
- Mailing ListPatchThird Party Advisory
- Issue TrackingPatchThird Party Advisory
- Vendor Advisory
- Issue TrackingRelease NotesVendor Advisory
- Issue TrackingRelease NotesVendor Advisory
- Mailing ListPatchThird Party Advisory
- Issue TrackingPatchThird Party Advisory
- Vendor Advisory
- Issue TrackingRelease NotesVendor Advisory
- Issue TrackingRelease NotesVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 5.1.21 (включая)Версия от 5.2.0 (включая) до 5.2.9 (исключая)
Одно из
cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*
cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*
EPSS
Процентиль: 62%
0.00433
Низкий
5.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 5.4
debian
около 8 лет назад
Stored XSS vulnerability in the Media Objects component of ILIAS befor ...
CVSS3: 5.4
github
больше 3 лет назад
Stored XSS vulnerability in the Media Objects component of ILIAS before 5.1.21 and 5.2.x before 5.2.9 allows an authenticated user to inject JavaScript to gain administrator privileges, related to the setParameter function in Services/MediaObjects/classes/class.ilMediaItem.php.
EPSS
Процентиль: 62%
0.00433
Низкий
5.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79