{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "versions": [
              {
                "introduced": "5.1.0"
              },
              {
                "fixed": "5.3.4"
              }
            ]
          },
          "events": [
            {
              "introduced": "1a4b8f71a3b4f5f753d847fa87258a214baeef06"
            },
            {
              "fixed": "aad29de0e53aaa23980fa34f4c4f37a1182e04a2"
            },
            {
              "fixed": "95870b2db3e71154102b2cd2f05334fc741c6e39"
            },
            {
              "fixed": "eb0272c8023818b1eb10a93e115c9e7960b62a62"
            }
          ],
          "repo": "https://github.com/ilias-elearning/ilias",
          "type": "GIT"
        }
      ]
    }
  ],
  "details": "Services/Form/classes/class.ilDateDurationInputGUI.php and Services/Form/classes/class.ilDateTimeInputGUI.php in ILIAS 5.1.x through 5.3.x before 5.3.4 allow XSS via an invalid date.",
  "id": "CVE-2018-10306",
  "modified": "2026-04-01T23:08:40.424157684Z",
  "published": "2018-05-18T13:29:00.330Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://www.ilias.de/docu/goto_docu_pg_116799_35.html"
    },
    {
      "type": "FIX",
      "url": "https://github.com/ILIAS-eLearning/ILIAS/commit/eb0272c8023818b1eb10a93e115c9e7960b62a62"
    },
    {
      "type": "FIX",
      "url": "https://github.com/ILIAS-eLearning/ILIAS/commit/95870b2db3e71154102b2cd2f05334fc741c6e39"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "type": "CVSS_V3"
    }
  ]
}