CVE-2018-10665: XSS
ILIAS 5.3.4 has XSS through unsanitized output of PHPSELF, related to shiblogout.php and third-party demo files.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this ILIAS version 5.3.4 vulnerability?
The vulnerability ID for this ILIAS version 5.3.4 vulnerability is CVE-2018-10665.
What is the severity rating of CVE-2018-10665?
The severity rating of CVE-2018-10665 is medium.
What is the CWE ID for CVE-2018-10665?
The CWE ID for CVE-2018-10665 is CWE-79.
How does the vulnerability CVE-2018-10665 occur?
The vulnerability CVE-2018-10665 occurs through unsanitized output of PHP_SELF.
Which files in ILIAS version 5.3.4 are related to the vulnerability CVE-2018-10665?
The files related to the vulnerability CVE-2018-10665 are shib_logout.php and third-party demo files.
Where can I find more information about the vulnerability CVE-2018-10665?
You can find more information about the vulnerability CVE-2018-10665 in the following references: [GitHub Commit 1](https://github.com/ILIAS-eLearning/ILIAS/commit/3fe6aa778ca06080cf1b7303cbc458aa0c42392a), [GitHub Commit 2](https://github.com/ILIAS-eLearning/ILIAS/commit/c9c9211bd689f2dda02006159e69a856eae8944d), [Open Bug Bounty Report](https://www.openbugbounty.org/reports/608858/).