CVE-2018-11119: Medium severity ilias vulnerability
Published May 17, 2018
·Updated
ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 redirects a logged-in user to a third-party site via the returntourl parameter.
Affected Software
7 affected components
ILIAS ILIAS>=5.1.0<=5.1.26
ILIAS ILIAS>=5.2.0<=5.2.15
ILIAS ILIAS>=5.3.0<=5.3.4
ILIAS ILIAS=5.1.0-beta1
ILIAS ILIAS=5.2.0-beta1
ILIAS ILIAS=5.2.0-beta2
ILIAS ILIAS=5.2.0-beta3
Remediation
Event History
May 17, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2018-11119.
2
What is the severity of CVE-2018-11119?
The severity of CVE-2018-11119 is medium with a CVSS score of 6.1.
3
Which versions of ILIAS are affected by CVE-2018-11119?
ILIAS versions 5.1.x, 5.2.x, and 5.3.x before 5.3.5 are affected by CVE-2018-11119.
4
How does CVE-2018-11119 exploit the vulnerability?
CVE-2018-11119 exploits the vulnerability by redirecting a logged-in user to a third-party site via the return_to_url parameter.
5
How can I fix CVE-2018-11119?
To fix CVE-2018-11119, upgrade to ILIAS version 5.3.5 or later.