CVE-2017-15538 Information
Feb 14, 2021
cve
Description
Stored XSS vulnerability in the Media Objects component of ILIAS before 5.1.21 and 5.2.x before 5.2.9 allows an authenticated user to inject JavaScript to gain administrator privileges related to the setParameter function in Services/MediaObjects/classes/class.ilMediaItem.php.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Reference
http://openwall.com/lists/oss-security/2017/10/17/3 https://github.com/ILIAS-eLearning/ILIAS/commit/b2a4660afec1e87d41c83c8e381f549bc6dfc70f https://lists.ilias.de/pipermail/ilias-admins/2017-October/000053.html https://www.ilias.de/docu/goto_docu_pg_75377_35.html https://www.ilias.de/docu/goto_docu_pg_75378_1719.html
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
5.4
Share on: