CVE-2018-11120: XSS
Published May 17, 2018
·Updated
Services/COPage/classes/class.ilPCSourceCode.php in ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 has XSS.
Affected Software
7 affected components
ILIAS ILIAS>=5.1.0<=5.1.26
ILIAS ILIAS>=5.2.0<=5.2.15
ILIAS ILIAS>=5.3.0<=5.3.4
ILIAS ILIAS=5.1.0-beta1
ILIAS ILIAS=5.2.0-beta1
ILIAS ILIAS=5.2.0-beta2
ILIAS ILIAS=5.2.0-beta3
Remediation
Event History
May 17, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-11120?
CVE-2018-11120 is a vulnerability in ILIAS versions 5.1.x, 5.2.x, and 5.3.x before 5.3.5 that allows for XSS attacks.
2
How does CVE-2018-11120 impact ILIAS?
CVE-2018-11120 can be exploited to perform XSS attacks on ILIAS versions 5.1.x, 5.2.x, and 5.3.x before 5.3.5.
3
What is the severity of CVE-2018-11120?
The severity of CVE-2018-11120 is medium with a CVSS score of 6.1.
4
How can I fix CVE-2018-11120?
To fix CVE-2018-11120, it is recommended to upgrade to ILIAS version 5.3.5 or later.
5
Where can I find more information about CVE-2018-11120?
More information about CVE-2018-11120 can be found at the following references: [GitHub](https://github.com/ILIAS-eLearning/ILIAS/commit/7959485406eb981976b64fee363cf950603924ed) and [ILIAS Documentation](https://www.ilias.de/docu/goto.php?target=st_229).