CVE-2018-10665
Dashboard / Vulnerabilities / CVE-2018-10665
CVE-2018-10665
Published: 2 May 2018Last Modified: 8 Jul 2026
Summary:
Details: ILIAS 5.3.4 has XSS through unsanitized output of PHP_SELF, related to shib_logout.php and third-party demo files.
References: https://www.openbugbounty.org/reports/608858/, https://github.com/ILIAS-eLearning/ILIAS/commit/3fe6aa778ca06080cf1b7303cbc458aa0c42392a, https://github.com/ILIAS-eLearning/ILIAS/commit/c9c9211bd689f2dda02006159e69a856eae8944d
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- aad29de0e53aaa23980fa34f4c4f37a1182e04a2
Fixed -None
Affected versions
5.3.4
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
