CVE-2024-33526

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-33526
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-33526.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-33526
Published
2024-05-21T15:15:28Z
Modified
2025-06-04T21:17:04Z
Summary
[none]
Details

A Stored Cross-site Scripting (XSS) vulnerability in the "Import of user role and title of user role" feature in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers with administrative privileges to inject arbitrary web script or HTML via XML file upload.

References

Affected packages

Git / github.com/ilias-elearning/ilias

Affected ranges

Type
GIT
Repo
https://github.com/ilias-elearning/ilias
Events