The UserTakeOver plugin before 4.0.1 for ILIAS allows an attacker to list all users via the search function.
References
| Link | Resource |
|---|---|
| https://medium.com/@bcksec/ilias-lms-usertakeover-4-0-1-vulnerability-b2824679403 | Third Party Advisory |
| https://github.com/srsolutionsag/UserTakeOver | Third Party Advisory |
Configurations
Information
Published : 2022-06-21 14:15
Updated : 2022-06-28 19:45
NVD link : CVE-2022-31478
Mitre link : CVE-2022-31478
JSON object : View
Products Affected
sr.solutions
- usertakeover
CWE
