CVE-2023-36488: XSS
Published Jun 29, 2023
·Updated
ILIAS 7.21 and 8.0beta1 through 8.2 is vulnerable to stored Cross Site Scripting (XSS).
Affected Software
2 affected components
ILIAS ILIAS>=8.0<=8.2
ILIAS ILIAS=7.21
Event History
Jun 29, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-36488?
CVE-2023-36488 is a vulnerability in ILIAS 7.21 and 8.0_beta1 through 8.2 that allows for stored Cross Site Scripting (XSS) attacks.
2
How severe is CVE-2023-36488?
CVE-2023-36488 has a severity rating of 5.4 (medium).
3
What software versions are affected by CVE-2023-36488?
ILIAS versions 7.21 and 8.0_beta1 through 8.2 are affected by CVE-2023-36488.
4
What is Cross Site Scripting (XSS)?
Cross Site Scripting (XSS) is a type of security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
5
How can I fix CVE-2023-36488?
To fix CVE-2023-36488, it is recommended to update ILIAS to a version that is not vulnerable.