CVE-2023-36486
- EPSS 0.67%
- Veröffentlicht 25.12.2023 08:15:07
- Zuletzt bearbeitet 21.11.2024 08:09:48
The workflow-engine of ILIAS before 7.23 and 8 before 8.3 allows remote authenticated users to run arbitrary system commands on the application server as the application user by uploading a workflow definition file with a malicious filename.
- EPSS 0.11%
- Veröffentlicht 26.10.2023 15:15:09
- Zuletzt bearbeitet 21.11.2024 08:27:31
ILIAS 7.25 (2023-09-12) allows any authenticated user to execute arbitrary operating system commands remotely, when a highly privileged account accesses an XSS payload. The injected commands are executed via the exec() function in the execQuoted() me...
CVE-2023-45868
- EPSS 0.29%
- Veröffentlicht 26.10.2023 15:15:08
- Zuletzt bearbeitet 21.11.2024 08:27:31
The Learning Module in ILIAS 7.25 (2023-09-12 release) allows an attacker (with basic user privileges) to achieve a high-impact Directory Traversal attack on confidentiality and availability. By exploiting this network-based vulnerability, the attack...
CVE-2023-45867
- EPSS 0.19%
- Veröffentlicht 26.10.2023 15:15:08
- Zuletzt bearbeitet 21.11.2024 08:27:31
ILIAS (2013-09-12 release) contains a medium-criticality Directory Traversal local file inclusion vulnerability in the ScormAicc module. An attacker with a privileged account, typically holding the tutor role, can exploit this to gain unauthorized ac...
CVE-2023-36484
- EPSS 0.11%
- Veröffentlicht 29.06.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:09:48
ILIAS 7.21 and 8.0_beta1 through 8.2 is vulnerable to reflected Cross-Site Scripting (XSS).
CVE-2023-36488
- EPSS 0.09%
- Veröffentlicht 29.06.2023 17:15:09
- Zuletzt bearbeitet 21.11.2024 08:09:49
ILIAS 7.21 and 8.0_beta1 through 8.2 is vulnerable to stored Cross Site Scripting (XSS).
CVE-2023-36487
- EPSS 0.44%
- Veröffentlicht 29.06.2023 17:15:09
- Zuletzt bearbeitet 26.11.2024 20:15:22
The password reset function in ILIAS 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows remote attackers to take over the account.
CVE-2022-45918
- EPSS 1.11%
- Veröffentlicht 07.12.2022 01:15:11
- Zuletzt bearbeitet 21.11.2024 07:29:57
ILIAS before 7.16 allows External Control of File Name or Path.
CVE-2022-45917
- EPSS 35.76%
- Veröffentlicht 07.12.2022 01:15:11
- Zuletzt bearbeitet 23.04.2025 18:16:02
ILIAS before 7.16 has an Open Redirect.
CVE-2022-45916
- EPSS 0.65%
- Veröffentlicht 07.12.2022 01:15:11
- Zuletzt bearbeitet 23.04.2025 18:16:02
ILIAS before 7.16 allows XSS.