8.8

CVE-2026-108113

ILIAS before 9.24, 10.12, and 11.5 Unrestricted File Upload via QTI Import

ILIAS before 9.24, 10.12, and 11.5 contains an unrestricted file upload vulnerability in QTI question import image handling (ilQtiMatImageSecurity) that allows authenticated authors to write executable files. Attackers with question pool import rights can import a crafted archive writing a .htaccess and PHP file to the web-served image directory, achieving remote code execution as the web server user.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerILIAS-eLearning e.V.
≫
Produkt ILIAS
Default Statusunaffected
Version 5.2.8
Version < 9.24
Status affected
Version 10.0
Version < 10.12
Status affected
Version 11.0
Version < 11.5
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
disclosure@vulncheck.com 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
disclosure@vulncheck.com 8.7 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

https://github.com/ILIAS-eLearning/ILIAS
https://docu.ilias.de/go/blog/15821/950
https://docu.ilias.de/go/blog/15821/951
https://docu.ilias.de/go/blog/15821/952
https://github.com/ILIAS-eLearning/ILIAS/commit/58ee5b1767212530f9948adb0e7d5aecec66ce60
https://github.com/ILIAS-eLearning/ILIAS/commit/5b200351330bee698432a45c0877c5bc694c367a
https://github.com/ILIAS-eLearning/ILIAS/commit/47c8462bf46bbebd543a9f3b39c7896b0e9e7362
https://github.com/ILIAS-eLearning/ILIAS/blob/v10.11/components/ILIAS/QTI/classes/class.ilQtiMatImageSecurity.php#L110-L122
https://www.vulncheck.com/advisories/ilias-before-9.24-10.12-and-11.5-unrestricted-file-upload-via-qti-import