VYPR
Unrated severityNVD Advisory· Published Jul 22, 2019· Updated Aug 5, 2024

CVE-2019-1010237

CVE-2019-1010237

Description

Ilias 5.3 before 5.3.12; 5.2 before 5.2.21 is affected by: Cross Site Scripting (XSS) - CWE-79 Type 2: Stored XSS (or Persistent). The impact is: Execute code in the victim's browser. The component is: Assessment / TestQuestionPool. The attack vector is: Cloze Test Text gap (attacker) / Corrections view (victim). The fixed version is: 5.3.12.

Affected products

1
  • Range: 5.3 before 5.3.12 and 5.2 before 5.2.21 [fixed: 5.3.12]

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.