← Vulnerability feed

Vulnerability record · CVE-2024-25974 · published 20 February 2024

CVE-2024-25974: Frentix openolat improper input validation vulnerability

Frentix · Openolat

The Frentix GmbH OpenOlat LMS is affected by stored a Cross-Site Scripting (XSS) vulnerability. It is possible to upload files within the Media Center of OpenOlat version 18.1.5 (or lower) as an authenticated user without any other rights. Although the filetypes are limited, an SVG image containing an XSS payload can be uploaded. After a successful upload the file can be shared with groups of users (including admins) who can be attacked with the JavaScript payload.

5.4 CVSS 3.1 Medium EPSS 0.55% · top 56.2% CWE-20 · Improper input validationCWE-79 · Cross-site scripting
5.4CVSS 3.1 base score
0.55%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Frentix GmbH OpenOlat LMS is affected by stored a Cross-Site Scripting (XSS) vulnerability. It is possible to upload files within the Media Center of OpenOlat version 18.1.5 (or lower) as an authenticated user without any other rights. Although the filetypes are limited, an SVG image containing an XSS payload can be uploaded. After a successful upload the file can be shared with groups of users (including admins) who can be attacked with the JavaScript payload.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://seclists.org/fulldisclosure/2024/Feb/23 ExploitMailing ListThird Party Advisory
https://r.sec-consult.com/openolat ExploitThird Party Advisory
http://seclists.org/fulldisclosure/2024/Feb/23 ExploitMailing ListThird Party Advisory
https://r.sec-consult.com/openolat ExploitThird Party Advisory

Track CVE-2024-25974 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-31946Frentix openolat improper authentication vulnerabilityOpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. From version 10.5.4 to before version …EPSS 0.33%8.8CVE-2026-28228Frentix openolat vulnerabilityOpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. Prior to versions 19.1.31, 20.1.18, an…EPSS 0.53%8.8CVE-2021-39181Frentix openolat xml injection vulnerabilityOpenOlat is a web-based learning management system (LMS). Prior to version 15.3.18, 15.5.3, and 16.0.0, using a prepared import XML file (e.g. a cour…EPSS 1.9%8.8CVE-2021-39180Frentix openolat path traversal vulnerabilityOpenOLAT is a web-based learning management system (LMS). A path traversal vulnerability exists in versions prior to 15.3.18, 15.5.3, and 16.0.0. Usi…EPSS 2.4%8.1CVE-2021-41242Frentix openolat relative path traversal vulnerabilityOpenOlat is a web-basedlearning management system. A path traversal vulnerability exists in OpenOlat prior to versions 15.5.12 and 16.0.5. By providi…EPSS 1.4%7.7CVE-2021-41152Frentix openolat path traversal vulnerabilityOpenOlat is a web-based e-learning platform for teaching, learning, assessment and communication, an LMS, a learning management system. In affected v…EPSS 1.2%7.5CVE-2024-28198Frentix openolat xml external entity (xxe) vulnerabilityOpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. By manually manipulating http requests…EPSS 0.43%5.4CVE-2024-25973Frentix openolat improper input validation vulnerabilityThe Frentix GmbH OpenOlat LMS is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities. An attacker with rights to create or edit gr…EPSS 0.56%

Source: NIST National Vulnerability Database (record CVE-2024-25974), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.