vendor:
ILIAS
by:
HauntIT Blog
8,8
CVSS
HIGH
Persistent XSS, Possibility of uploading webshell, XSS
79, 434, 79
CWE
Product Name: ILIAS
Affected Version From: ilias-4.4.1.zip
Affected Version To: ilias-4.4.1.zip
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2014
Multiple vulnerabilities in ILIAS
First from admin user logged in, an attacker can exploit a persistent XSS vulnerability by sending a POST request with malicious payload. An attacker can also upload a webshell in the ILIAS directories and access it directly to gain a webshell. An attacker can also exploit an XSS vulnerability by sending a POST request with malicious payload.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in the application. Ensure that the application is running the latest version of the software.