CVE-2019-1010237: XSS
Published Jul 22, 2019
·Updated
Ilias 5.3 before 5.3.12; 5.2 before 5.2.21 is affected by: Cross Site Scripting (XSS) - CWE-79 Type 2: Stored XSS (or Persistent). The impact is: Execute code in the victim's browser. The component is: Assessment / TestQuestionPool. The attack vector is: Cloze Test Text gap (attacker) / Corrections view (victim). The fixed version is: 5.3.12.
Affected Software
2 affected components
ILIAS ILIAS>=5.2.0<5.2.21
ILIAS ILIAS>=5.3.0<5.3.12
Remediation
Event History
Jul 22, 2019
CVE Published
via MITRE·02:46 PM
Data Sourced
via MITRE·02:46 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-1010237?
The severity of CVE-2019-1010237 is medium with a CVSS score of 6.1.
2
How does CVE-2019-1010237 affect Ilias?
CVE-2019-1010237 affects Ilias versions 5.3 before 5.3.12 and 5.2 before 5.2.21.
3
What is the impact of CVE-2019-1010237?
The impact of CVE-2019-1010237 is the ability to execute code in the victim's browser.
4
Which component of Ilias is affected by CVE-2019-1010237?
CVE-2019-1010237 affects the Assessment / TestQuestionPool component of Ilias.
5
How can I fix CVE-2019-1010237?
To fix CVE-2019-1010237, update Ilias to version 5.3.12 or 5.2.21.