cvedb.io
CVE-2017-15538
MEDIUM · CVSS 5.4
EPSS exploitation probability: 0%
Published 2017-10-17T20:29:00.197 · Last modified 2026-06-17T01:07:52.080

Summary

Stored XSS vulnerability in the Media Objects component of ILIAS before 5.1.21 and 5.2.x before 5.2.9 allows an authenticated user to inject JavaScript to gain administrator privileges, related to the setParameter function in Services/MediaObjects/classes/class.ilMediaItem.php.

Affected products

ilias — ilias

Does this affect you?

Add your gear to cvedb and we'll alert you only when ilias ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.