CVE-2017-15538: XSS
Published Oct 17, 2017
·Updated
Stored XSS vulnerability in the Media Objects component of ILIAS before 5.1.21 and 5.2.x before 5.2.9 allows an authenticated user to inject JavaScript to gain administrator privileges, related to the setParameter function in Services/MediaObjects/classes/class.ilMediaItem.php.
Affected Software
2 affected components
ILIAS ILIAS<=5.1.21
ILIAS ILIAS>=5.2.0<5.2.9
Remediation
Patch Available
Event History
Oct 17, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-15538?
CVE-2017-15538 has a medium severity rating of 5.4.
2
How do I fix CVE-2017-15538?
To fix CVE-2017-15538, update ILIAS to version 5.1.21 or 5.2.9 and later.
3
What type of vulnerability is CVE-2017-15538?
CVE-2017-15538 is a stored cross-site scripting (XSS) vulnerability.
4
Which versions of ILIAS are affected by CVE-2017-15538?
ILIAD versions before 5.1.21 and 5.2.x before 5.2.9 are affected by CVE-2017-15538.
5
Who can exploit CVE-2017-15538?
CVE-2017-15538 can be exploited by authenticated users to inject JavaScript into the application.