High severity7.1NVD Advisory· Published May 21, 2024· Updated Jun 17, 2026
CVE-2024-33526
CVE-2024-33526
Description
A Stored Cross-site Scripting (XSS) vulnerability in the "Import of user role and title of user role" feature in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers with administrative privileges to inject arbitrary web script or HTML via XML file upload.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- docu.ilias.de/ilias.phpnvdPatch
- insinuator.net/2024/05/security-advisory-achieving-php-code-execution-in-ilias-elearning-lms-before-v7-30-v8-11-v9-1/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.