cvelist/2024/25xxx/CVE-2024-25974.json
2024-02-21 08:00:36 +00:00

99 lines
3.4 KiB
JSON

{
"data_version": "4.0",
"data_type": "CVE",
"data_format": "MITRE",
"CVE_data_meta": {
"ID": "CVE-2024-25974",
"ASSIGNER": "security-research@sec-consult.com",
"STATE": "PUBLIC"
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "The Frentix GmbH OpenOlat LMS is affected by stored a Cross-Site Scripting (XSS) vulnerability.\u00a0It is possible to upload files within the Media Center of OpenOlat version 18.1.5 (or lower) as an authenticated user without any other rights. Although the filetypes are limited, an SVG image containing an XSS payload can be uploaded.\u00a0After a successful upload the file can be shared with groups of users (including admins) who can be attacked with the JavaScript payload."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-20 Improper Input Validation",
"cweId": "CWE-20"
}
]
}
]
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "Frentix GmbH",
"product": {
"product_data": [
{
"product_name": "OpenOlat LMS",
"version": {
"version_data": [
{
"version_affected": "<=",
"version_name": "0",
"version_value": "18.1.5"
}
]
}
}
]
}
}
]
}
},
"references": {
"reference_data": [
{
"url": "https://r.sec-consult.com/openolat",
"refsource": "MISC",
"name": "https://r.sec-consult.com/openolat"
},
{
"url": "http://seclists.org/fulldisclosure/2024/Feb/23",
"refsource": "MISC",
"name": "http://seclists.org/fulldisclosure/2024/Feb/23"
}
]
},
"generator": {
"engine": "Vulnogram 0.1.0-dev"
},
"source": {
"discovery": "EXTERNAL"
},
"solution": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<span style=\"background-color: rgb(255, 255, 255);\">The vendor provides a patched version 18.1.6 or higher for the mentioned vulnerabilities.</span><br><br>"
}
],
"value": "The vendor provides a patched version 18.1.6 or higher for the mentioned vulnerabilities.\n\n"
}
],
"credits": [
{
"lang": "en",
"value": "Mike Klostermaier (SEC Consult Vulnerability Lab)"
},
{
"lang": "en",
"value": "Johannes V\u00f6lpel (SEC Consult Vulnerability Lab)"
}
]
}