VYPR
Medium severity6.1NVD Advisory· Published Jul 22, 2019· Updated Jun 17, 2026

CVE-2019-1010237

CVE-2019-1010237

Description

Ilias 5.3 before 5.3.12; 5.2 before 5.2.21 is affected by: Cross Site Scripting (XSS) - CWE-79 Type 2: Stored XSS (or Persistent). The impact is: Execute code in the victim's browser. The component is: Assessment / TestQuestionPool. The attack vector is: Cloze Test Text gap (attacker) / Corrections view (victim). The fixed version is: 5.3.12.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Ilias/Ilias3 versions
    cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*range: >=5.2.0,<5.2.21
    • (no CPE)range: <5.3.12, <5.2.21
    • (no CPE)range: 5.3 before 5.3.12 and 5.2 before 5.2.21 [fixed: 5.3.12]

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.