Ilias 5.3 before 5.3.12; 5.2 before 5.2.21 is affected by: Cross Site Scripting (XSS) - CWE-79 Type 2: Stored XSS (or Persistent). The impact is: Execute code in the victim's browser. The component is: Assessment / TestQuestionPool. The attack vector is: Cloze Test Text gap (attacker) / Corrections view (victim). The fixed version is: 5.3.12.
{
"source": [
"CPE_RANGE",
"REFERENCES"
],
"cpe": "cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "5.2.0"
},
{
"fixed": "5.2.21"
},
{
"introduced": "5.3.0"
},
{
"fixed": "5.3.12"
}
]
}