CVE-2024-33526: XSS
A Stored Cross-site Scripting (XSS) vulnerability in the "Import of user role and title of user role" feature in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers with administrative privileges to inject arbitrary web script or HTML via XML file upload.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33526?
CVE-2024-33526 is considered a high severity vulnerability due to the potential for remote authenticated attackers to inject arbitrary web scripts or HTML.
How do I fix CVE-2024-33526?
To fix CVE-2024-33526, upgrade ILIAS to version 7.30 or later or version 8.11 or later.
Who is affected by CVE-2024-33526?
CVE-2024-33526 affects all users of ILIAS versions prior to 7.30 and 8.11 who have administrative privileges.
What type of vulnerability is CVE-2024-33526?
CVE-2024-33526 is a Stored Cross-site Scripting (XSS) vulnerability.
What can attackers achieve with CVE-2024-33526?
Attackers with administrative privileges can use CVE-2024-33526 to inject and execute arbitrary web scripts or HTML.