CVE-2024-25974 - CVE House
Back to Database
Status published Unknown CVE-2024-25974

Stored Cross-Site Scripting (XSS) within the Media Center

Vulnerability Description

The Frentix GmbH OpenOlat LMS is affected by stored a Cross-Site Scripting (XSS) vulnerability. It is possible to upload files within the Media Center of OpenOlat version 18.1.5 (or lower) as an authenticated user without any other rights. Although the filetypes are limited, an SVG image containing an XSS payload can be uploaded. After a successful upload the file can be shared with groups of users (including admins) who can be attacked with the JavaScript payload.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-25974

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Mike Klostermaier (SEC Consult Vulnerability Lab)
  • Johannes Völpel (SEC Consult Vulnerability Lab)

Affected Vendor

Frentix GmbH

View all reports →

Affected Software

OpenOlat LMS
Vulnerable Versions:
0

Timeline

Official Publish: February 20th, 2024
Last Modified: February 13th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)