Back to search
CVE-2019-1010237
Published: Jul 22, 2019
Modified: Aug 5, 2024
PUBLISHED
Description
Ilias 5.3 before 5.3.12; 5.2 before 5.2.21 is affected by: Cross Site Scripting (XSS) - CWE-79 Type 2: Stored XSS (or Persistent). The impact is: Execute code in the victim's browser. The component is: Assessment / TestQuestionPool. The attack vector is: Cloze Test Text gap (attacker) / Corrections view (victim). The fixed version is: 5.3.12.
| Vendor | Product | Versions |
|---|---|---|
Ilias | Ilias | affected 5.3 before 5.3.12 and 5.2 before 5.2.21 [fixed: 5.3.12] |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now