CVE-2024-33527: XSS
A Stored Cross-site Scripting (XSS) vulnerability in the "Import of Users and login name of user" feature in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers with administrative privileges to inject arbitrary web script or HTML via XML file upload.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33527?
CVE-2024-33527 is classified as a high severity vulnerability due to its potential for allowing remote attackers to inject malicious scripts.
How do I fix CVE-2024-33527?
To fix CVE-2024-33527, you should update ILIAS to version 7.30 or later for ILIAS 7, and to version 8.11 or later for ILIAS 8.
Who is affected by CVE-2024-33527?
CVE-2024-33527 affects remote authenticated users with administrative privileges in ILIAS versions before 7.30 and 8.11.
What type of vulnerability is CVE-2024-33527?
CVE-2024-33527 is a Stored Cross-site Scripting (XSS) vulnerability.
What feature is vulnerable in CVE-2024-33527?
The vulnerability is in the "Import of Users and login name of user" feature of ILIAS.