Show filters
34 Total Results
Displaying 11-20 of 34
Sort by:
Attacker Value
Unknown

CVE-2022-45916

Disclosure Date: December 07, 2022 (last updated October 08, 2023)
ILIAS before 7.16 allows XSS.
Attacker Value
Unknown

CVE-2022-45915

Disclosure Date: December 07, 2022 (last updated October 08, 2023)
ILIAS before 7.16 allows OS Command Injection.
Attacker Value
Unknown

CVE-2022-31266

Disclosure Date: June 29, 2022 (last updated November 05, 2024)
In ILIAS through 7.10, lack of verification when changing an email address (on the Profile Page) allows remote attackers to take over accounts.
Attacker Value
Unknown

CVE-2020-23995

Disclosure Date: May 13, 2021 (last updated February 22, 2025)
An information disclosure vulnerability in ILIAS before 5.3.19, 5.4.12 and 6.0 allows remote authenticated attackers to get the upload data path via a workspace upload.
Attacker Value
Unknown

CVE-2020-23996

Disclosure Date: May 13, 2021 (last updated February 22, 2025)
A local file inclusion vulnerability in ILIAS before 5.3.19, 5.4.10 and 6.0 allows remote authenticated attackers to execute arbitrary code via the import of personal data.
Attacker Value
Unknown

CVE-2020-25267

Disclosure Date: November 10, 2020 (last updated February 22, 2025)
An XSS issue exists in the question-pool file-upload preview feature in ILIAS 6.4.
Attacker Value
Unknown

CVE-2020-25268

Disclosure Date: November 10, 2020 (last updated February 22, 2025)
Remote Code Execution can occur via the external news feed in ILIAS 6.4 because of incorrect parameter sanitization for Magpie RSS data.
Attacker Value
Unknown

CVE-2019-1010237

Disclosure Date: July 22, 2019 (last updated November 27, 2024)
Ilias 5.3 before 5.3.12; 5.2 before 5.2.21 is affected by: Cross Site Scripting (XSS) - CWE-79 Type 2: Stored XSS (or Persistent). The impact is: Execute code in the victim's browser. The component is: Assessment / TestQuestionPool. The attack vector is: Cloze Test Text gap (attacker) / Corrections view (victim). The fixed version is: 5.3.12.
0
Attacker Value
Unknown

CVE-2018-10428

Disclosure Date: May 23, 2018 (last updated November 26, 2024)
ILIAS before 5.1.26, 5.2.x before 5.2.15, and 5.3.x before 5.3.4, due to inconsistencies in parameter handling, is vulnerable to various instances of reflected cross-site-scripting.
0
Attacker Value
Unknown

CVE-2018-10307

Disclosure Date: May 18, 2018 (last updated November 26, 2024)
error.php in ILIAS 5.2.x through 5.3.x before 5.3.4 allows XSS via the text of a PDO exception.
0