Security Advisory

CVE-2024-33525

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-05-21 18:50:39
Last updated 2025-02-13 15:52:40
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

A Stored Cross-site Scripting (XSS) vulnerability in the "Import of organizational units and title of organizational unit" feature in ILIAS 7.20 to 7.29 and ILIAS 8.4 to 8.10 as well as ILIAS 9.0 allows remote authenticated attackers with administrative privileges to inject arbitrary web script or HTML via XML file upload.