CVE-2014-2090: Ilias

Low severity, CVSS 3.5. EPSS: 1.4% chance of exploitation in the next 30 days.

Multiple cross-site scripting (XSS) vulnerabilities in ilias.php in ILIAS 4.4.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) tar, (2) tar_val, or (3) title parameter.

Affected products

  • Ilias Ilias: version 4.4.1 only

Published 2014-03-02. Last modified 2026-06-17.