Frentix

Openolat

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.11%
  • Veröffentlicht 11.03.2024 20:15:07
  • Zuletzt bearbeitet 10.04.2025 20:46:19

OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. By manually manipulating http requests when using the draw.io integration it is possible to read arbitrary files as the configured system u...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 20.02.2024 08:15:07
  • Zuletzt bearbeitet 14.03.2025 02:15:13

The Frentix GmbH OpenOlat LMS is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities. An attacker with rights to create or edit groups can create a course with a name that contains an XSS payload. Furthermore, attackers with the pe...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 20.02.2024 08:15:07
  • Zuletzt bearbeitet 02.04.2025 20:10:53

The Frentix GmbH OpenOlat LMS is affected by stored a Cross-Site Scripting (XSS) vulnerability. It is possible to upload files within the Media Center of OpenOlat version 18.1.5 (or lower) as an authenticated user without any other rights. Although t...

  • EPSS 0.79%
  • Veröffentlicht 10.12.2021 23:15:09
  • Zuletzt bearbeitet 21.11.2024 06:25:51

OpenOlat is a web-basedlearning management system. A path traversal vulnerability exists in OpenOlat prior to versions 15.5.12 and 16.0.5. By providing a filename that contains a relative path as a parameter in some REST methods, it is possible to cr...

  • EPSS 0.54%
  • Veröffentlicht 18.10.2021 21:15:08
  • Zuletzt bearbeitet 21.11.2024 06:25:36

OpenOlat is a web-based e-learning platform for teaching, learning, assessment and communication, an LMS, a learning management system. In affected versions by manipulating the HTTP request an attacker can modify the path of a requested file download...

  • EPSS 0.55%
  • Veröffentlicht 01.09.2021 20:15:07
  • Zuletzt bearbeitet 21.11.2024 06:18:49

OpenOlat is a web-based learning management system (LMS). Prior to version 15.3.18, 15.5.3, and 16.0.0, using a prepared import XML file (e.g. a course) any class on the Java classpath can be instantiated, including spring AOP bean factories. This ca...

  • EPSS 1.22%
  • Veröffentlicht 31.08.2021 18:15:08
  • Zuletzt bearbeitet 21.11.2024 06:18:48

OpenOLAT is a web-based learning management system (LMS). A path traversal vulnerability exists in versions prior to 15.3.18, 15.5.3, and 16.0.0. Using a specially prepared ZIP file, it is possible to overwrite any file that is writable by the applic...