The Frentix GmbH OpenOlat LMS is affected by stored a Cross-Site Scripting (XSS) vulnerability. It is possible to upload files within the Media Center of OpenOlat version 18.1.5 (or lower) as an authenticated user without any other rights. Although the filetypes are limited, an SVG image containing an XSS payload can be uploaded. After a successful upload the file can be shared with groups of users (including admins) who can be attacked with the JavaScript payload.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Apr 2025 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:a:frentix:openolat:*:*:*:*:*:*:*:* |
Thu, 13 Feb 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Frentix
Frentix openolat |
|
CPEs | cpe:2.3:a:frentix:openolat:-:*:*:*:*:*:*:* | |
Vendors & Products |
Frentix
Frentix openolat |
|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: SEC-VLab
Published:
Updated: 2025-02-13T17:40:56.325Z
Reserved: 2024-02-13T09:28:28.809Z
Link: CVE-2024-25974

Updated: 2024-08-01T23:52:06.435Z

Status : Analyzed
Published: 2024-02-20T08:15:07.823
Modified: 2025-04-02T20:10:53.337
Link: CVE-2024-25974

No data.