CVE-2018-5688: XSS
Published Jan 14, 2018
·Updated
ILIAS before 5.2.4 has XSS via the cmd parameter to the displayHeader function in setup/classes/class.ilSetupGUI.php in the Setup component.
Affected Software
1 affected component
ILIAS ILIAS<5.2.4
Remediation
Event History
Jan 14, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of ILIAS?
The vulnerability ID of ILIAS is CVE-2018-5688.
2
What is the severity rating of CVE-2018-5688?
The severity rating of CVE-2018-5688 is medium with a value of 6.1.
3
How does the XSS vulnerability in ILIAS before 5.2.4 occur?
The XSS vulnerability in ILIAS before 5.2.4 occurs via the cmd parameter to the displayHeader function in setup/classes/class.ilSetupGUI.php in the Setup component.
4
What is the affected software for CVE-2018-5688?
The affected software for CVE-2018-5688 is Ilias before version 5.2.4.
5
How can I fix the XSS vulnerability in ILIAS?
To fix the XSS vulnerability in ILIAS, update to version 5.2.4 or later.