CVE-2018-10428: XSS
Published May 23, 2018
·Updated
ILIAS before 5.1.26, 5.2.x before 5.2.15, and 5.3.x before 5.3.4, due to inconsistencies in parameter handling, is vulnerable to various instances of reflected cross-site-scripting.
Affected Software
3 affected components
ILIAS ILIAS<5.1.26
ILIAS ILIAS>=5.2.0<5.2.15
ILIAS ILIAS>=5.3.0<5.3.4
Event History
May 23, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-10428.
2
What is the severity of CVE-2018-10428?
CVE-2018-10428 has a severity of medium.
3
What software versions are affected by CVE-2018-10428?
ILIAS versions before 5.1.26, 5.2.x before 5.2.15, and 5.3.x before 5.3.4 are affected by CVE-2018-10428.
4
What type of vulnerability is CVE-2018-10428?
CVE-2018-10428 is a reflected cross-site scripting (XSS) vulnerability.
5
How can I fix CVE-2018-10428?
To fix CVE-2018-10428, upgrade to ILIAS version 5.1.26, 5.2.15, or 5.3.4 or later.