CVE-2017-15538: Ilias
Medium severity, CVSS 5.4. EPSS: 0.9% chance of exploitation in the next 30 days.
Stored XSS vulnerability in the Media Objects component of ILIAS before 5.1.21 and 5.2.x before 5.2.9 allows an authenticated user to inject JavaScript to gain administrator privileges, related to the setParameter function in Services/MediaObjects/classes/class.ilMediaItem.php.
Affected products
- Ilias Ilias: up to and including 5.1.21; from 5.2.0, before 5.2.9 (fixed in 5.2.9)
Published 2017-10-17. Last modified 2026-06-17.