CVE-2018-10306: XSS
Published May 18, 2018
·Updated
Services/Form/classes/class.ilDateDurationInputGUI.php and Services/Form/classes/class.ilDateTimeInputGUI.php in ILIAS 5.1.x through 5.3.x before 5.3.4 allow XSS via an invalid date.
Affected Software
1 affected component
ILIAS ILIAS>=5.1.0<5.3.4
Remediation
Event History
May 18, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-10306.
2
What is the title of this vulnerability?
The title of this vulnerability is Services/Form/classes/class.ilDateDurationInputGUI.php and Services/Form/classes/class.ilDateTimeInputGUI.php in ILIAS 5.1.x through 5.3.x before 5.3.4 allow XSS via an invalid date.
3
What is the affected software?
The affected software is ILIAS version 5.1.x through 5.3.x before 5.3.4.
4
How severe is this vulnerability?
The severity of this vulnerability is medium with a CVSS score of 6.1.
5
How can I fix this vulnerability?
To fix this vulnerability, you should update ILIAS to version 5.3.4 or later.