← Back to CVE List

CVE-2024-33527

Published: 2024-05-21T15:15Z
Last Modified: 2024-11-21T09:17Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A Stored Cross-site Scripting (XSS) vulnerability in the "Import of Users and login name of user" feature in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers with administrative privileges to inject arbitrary web script or HTML via XML file upload. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt