CVE-2020-25267: XSS
Published Nov 10, 2020
·Updated
An XSS issue exists in the question-pool file-upload preview feature in ILIAS 6.4.
Affected Software
1 affected component
ILIAS ILIAS=6.4.0
Event History
Nov 10, 2020
CVE Published
via MITRE·09:45 PM
Data Sourced
via MITRE·09:45 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue in ILIAS 6.4?
The vulnerability ID for this issue in ILIAS 6.4 is CVE-2020-25267.
2
What is the severity of CVE-2020-25267?
The severity of CVE-2020-25267 is medium with a CVSS score of 5.4.
3
What is the affected software version for CVE-2020-25267?
The affected software version for CVE-2020-25267 is ILIAS 6.4.0.
4
What is the CWE category for CVE-2020-25267?
The CWE category for CVE-2020-25267 is CWE-79 (Cross-Site Scripting).
5
How can I fix the XSS issue in ILIAS 6.4?
To fix the XSS issue in ILIAS 6.4, you should update to the latest version of ILIAS and apply any available patches or security updates.