The Frentix GmbH OpenOlat LMS is affected by stored a Cross-Site Scripting (XSS) vulnerability. It is possible to upload files within the Media Center of OpenOlat version 18.1.5 (or lower) as an authenticated user without any other rights. Although the filetypes are limited, an SVG image containing an XSS payload can be uploaded. After a successful upload the file can be shared with groups of users (including admins) who can be attacked with the JavaScript payload.
Cite this page
CVE-2024-25974. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2024-25974
Use CWE-20, Frentix vendor hub and Openolat product page to widen CVE-2024-25974 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-31946, CVE-2026-28228 and CVE-2021-39181 for nearby disclosures in the same product family.