CVE-2018-11118: XSS
Published May 17, 2018
·Updated
The RSS subsystem in ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 has XSS via a URI to Services/Feeds/classes/class.ilExternalFeedItem.php.
Affected Software
7 affected components
ILIAS ILIAS>=5.1.0<=5.1.26
ILIAS ILIAS>=5.2.0<=5.2.15
ILIAS ILIAS>=5.3.0<=5.3.4
ILIAS ILIAS=5.1.0-beta1
ILIAS ILIAS=5.2.0-beta1
ILIAS ILIAS=5.2.0-beta2
ILIAS ILIAS=5.2.0-beta3
Remediation
Event History
May 17, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-11118?
CVE-2018-11118 is a vulnerability in the RSS subsystem of ILIAS versions 5.1.x, 5.2.x, and 5.3.x before 5.3.5 that allows for cross-site scripting (XSS) attacks via a URI to Services/Feeds/classes/class.ilExternalFeedItem.php.
2
How severe is CVE-2018-11118?
CVE-2018-11118 has a severity level of 6.1 (medium).
3
How can I fix CVE-2018-11118?
To fix CVE-2018-11118, it is recommended to update to ILIAS version 5.3.5 or later.
4
What is ILIAS?
ILIAS is an open-source learning management system (LMS) used for e-learning.
5
Where can I find more information about CVE-2018-11118?
More information about CVE-2018-11118 can be found on the ILIAS website and the associated GitHub commits.