The UserTakeOver plugin before 4.0.1 for ILIAS allows an attacker to list all users via the search function.
References
Link | Resource |
---|---|
https://medium.com/@bcksec/ilias-lms-usertakeover-4-0-1-vulnerability-b2824679403 | Third Party Advisory |
https://github.com/srsolutionsag/UserTakeOver | Third Party Advisory |
Configurations
Information
Published : 2022-06-21 07:15
Updated : 2022-06-28 12:45
NVD link : CVE-2022-31478
Mitre link : CVE-2022-31478
JSON object : View
CWE
Products Affected
sr.solutions
- usertakeover