Ilias

Ilias

43 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.03%
  • Veröffentlicht 28.01.2026 17:35:07
  • Zuletzt bearbeitet 09.02.2026 18:13:36

ILIAS Learning Management System 4.3 contains a server-side request forgery vulnerability that allows attackers to read local files through portfolio PDF export functionality. Attackers can inject a script that uses XMLHttpRequest to retrieve local f...

  • EPSS 0.05%
  • Veröffentlicht 06.10.2025 19:32:05
  • Zuletzt bearbeitet 23.01.2026 19:15:52

A vulnerability has been found in ILIAS up to 8.23/9.13/10.1. This affects the function unserialize of the component Base64 Decoding Handler. Such manipulation of the argument f_settings leads to deserialization. It is possible to launch the attack r...

  • EPSS 0.11%
  • Veröffentlicht 06.10.2025 19:15:34
  • Zuletzt bearbeitet 23.01.2026 19:15:52

A flaw has been found in ILIAS up to 8.23/9.13/10.1. Affected by this issue is the function unserialize of the component Test Import. This manipulation causes deserialization. It is possible to initiate the attack remotely. Upgrading to version 8.24,...

  • EPSS 0.12%
  • Veröffentlicht 06.10.2025 18:32:05
  • Zuletzt bearbeitet 23.01.2026 19:15:51

A vulnerability was detected in ILIAS up to 8.23/9.13/10.1. Affected by this vulnerability is an unknown functionality of the component Certificate Import Handler. The manipulation results in Remote Code Execution. The attack may be performed from re...

  • EPSS 0.06%
  • Veröffentlicht 21.05.2024 19:15:10
  • Zuletzt bearbeitet 21.11.2024 09:17:04

A Stored Cross-site Scripting (XSS) vulnerability in the "Import of organizational units and title of organizational unit" feature in ILIAS 7.20 to 7.29 and ILIAS 8.4 to 8.10 as well as ILIAS 9.0 allows remote authenticated attackers with administrat...

Exploit
  • EPSS 1.16%
  • Veröffentlicht 21.05.2024 15:15:29
  • Zuletzt bearbeitet 04.06.2025 17:27:26

ILIAS 7 before 7.30 and ILIAS 8 before 8.11 as well as ILIAS 9.0 allow remote authenticated attackers with administrative privileges to execute operating system commands via file uploads with dangerous types.

Exploit
  • EPSS 0.12%
  • Veröffentlicht 21.05.2024 15:15:29
  • Zuletzt bearbeitet 04.06.2025 17:27:37

A Stored Cross-site Scripting (XSS) vulnerability in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers with tutor privileges to inject arbitrary web script or HTML via XML file upload.

Exploit
  • EPSS 0.04%
  • Veröffentlicht 21.05.2024 15:15:29
  • Zuletzt bearbeitet 04.06.2025 17:27:43

A Stored Cross-site Scripting (XSS) vulnerability in the "Import of Users and login name of user" feature in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers with administrative privileges to inject arbitrary web scri...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 21.05.2024 15:15:28
  • Zuletzt bearbeitet 04.06.2025 17:27:49

A Stored Cross-site Scripting (XSS) vulnerability in the "Import of user role and title of user role" feature in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers with administrative privileges to inject arbitrary web ...

  • EPSS 0.67%
  • Veröffentlicht 25.12.2023 08:15:07
  • Zuletzt bearbeitet 21.11.2024 08:09:48

The workflow-engine of ILIAS before 7.23 and 8 before 8.3 allows remote authenticated users to run arbitrary system commands on the application server as the application user via a malicious BPMN2 workflow definition file.