CVE-2024-33527: Ilias
Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.
A Stored Cross-site Scripting (XSS) vulnerability in the "Import of Users and login name of user" feature in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers with administrative privileges to inject arbitrary web script or HTML via XML file upload.
Affected products
- Ilias Ilias: from 7.0, before 7.30 (fixed in 7.30); from 8.0, before 8.11 (fixed in 8.11)
Published 2024-05-21. Last modified 2026-06-17.