CVE-2018-11117: XSS
Published May 17, 2018
·Updated
Services/Feeds/classes/class.ilExternalFeedItem.php in ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 has XSS via a link attribute.
Affected Software
7 affected components
ILIAS ILIAS>=5.1.0<=5.1.26
ILIAS ILIAS>=5.2.0<=5.2.15
ILIAS ILIAS>=5.3.0<=5.3.4
ILIAS ILIAS=5.1.0-beta1
ILIAS ILIAS=5.2.0-beta1
ILIAS ILIAS=5.2.0-beta2
ILIAS ILIAS=5.2.0-beta3
Remediation
Event History
May 17, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-11117?
CVE-2018-11117 is a vulnerability in ILIAS, versions 5.1.x, 5.2.x, and 5.3.x before 5.3.5, that allows for XSS attacks via a link attribute.
2
What is the severity of CVE-2018-11117?
The severity of CVE-2018-11117 is medium with a CVSS score of 6.1.
3
How does CVE-2018-11117 affect ILIAS?
CVE-2018-11117 affects ILIAS versions 5.1.x, 5.2.x, and 5.3.x before 5.3.5.
4
How can I fix CVE-2018-11117?
To fix CVE-2018-11117, update your ILIAS installation to version 5.3.5 or later.
5
Where can I find more information about CVE-2018-11117?
You can find more information about CVE-2018-11117 at the following references: [GitHub Commit](https://github.com/ILIAS-eLearning/ILIAS/commit/ff9bf29858f2dbffe828711a6f8bf37038c00d77), [ILIAS Documentation](https://www.ilias.de/docu/goto.php?target=st_229).