CVE-2024-33528: XSS
Published May 21, 2024
·Updated
A Stored Cross-site Scripting (XSS) vulnerability in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers with tutor privileges to inject arbitrary web script or HTML via XML file upload.
Affected Software
4 affected components
ILIAS ILIAS<7.30
ILIAS ILIAS<8.11
ILIAS ILIAS>=7.0<7.30
ILIAS ILIAS>=8.0<8.11
Remediation
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 21, 2024
CVE Published
via NVD·03:15 PM
Nov 4, 2024
Data Sourced
via MITRE·04:44 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-33528?
CVE-2024-33528 is considered a high-severity vulnerability due to the potential for remote code execution via XSS.
2
How do I fix CVE-2024-33528?
To fix CVE-2024-33528, upgrade ILIAS to version 7.30 or later for the 7 series, and version 8.11 or later for the 8 series.
3
Who is affected by CVE-2024-33528?
CVE-2024-33528 affects users of ILIAS versions prior to 7.30 and 8.11 who have tutor privileges.
4
What type of vulnerability is CVE-2024-33528?
CVE-2024-33528 is a Stored Cross-site Scripting (XSS) vulnerability.
5
Can I exploit CVE-2024-33528 remotely?
Yes, CVE-2024-33528 can be exploited remotely by authenticated users with tutor privileges.