Vulnerabilities > Ilias > Ilias > 5.1.27

DATE CVE VULNERABILITY TITLE RISK
2018-01-14 CVE-2018-5688 Cross-site Scripting vulnerability in Ilias
ILIAS before 5.2.4 has XSS via the cmd parameter to the displayHeader function in setup/classes/class.ilSetupGUI.php in the Setup component.
network
ilias CWE-79
4.3
2017-04-07 CVE-2017-7583 Cross-site Scripting vulnerability in Ilias
ILIAS before 5.2.3 has XSS via SVG documents.
network
ilias CWE-79
4.3