The UserTakeOver plugin before 4.0.1 for ILIAS allows an attacker to list all users via the search function.
References
| Link | Resource |
|---|---|
| https://github.com/srsolutionsag/UserTakeOver | Third Party Advisory |
| https://medium.com/%40bcksec/ilias-lms-usertakeover-4-0-1-vulnerability-b2824679403 |
Configurations
History
07 Nov 2023, 03:47
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
Information
Published : 2022-06-21 14:15
Updated : 2023-11-07 03:47
NVD link : CVE-2022-31478
Mitre link : CVE-2022-31478
JSON object : View
Products Affected
sr.solutions
- usertakeover
CWE
