CVE-2023-45867
- EPSS 0.89%
- Veröffentlicht 26.10.2023 15:15:08
- Zuletzt bearbeitet 21.11.2024 08:27:31
ILIAS (2013-09-12 release) contains a medium-criticality Directory Traversal local file inclusion vulnerability in the ScormAicc module. An attacker with a privileged account, typically holding the tutor role, can exploit this to gain unauthorized ac...
CVE-2023-36484
- EPSS 0.42%
- Veröffentlicht 29.06.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:09:48
ILIAS 7.21 and 8.0_beta1 through 8.2 is vulnerable to reflected Cross-Site Scripting (XSS).
CVE-2023-36488
- EPSS 0.39%
- Veröffentlicht 29.06.2023 17:15:09
- Zuletzt bearbeitet 21.11.2024 08:09:49
ILIAS 7.21 and 8.0_beta1 through 8.2 is vulnerable to stored Cross Site Scripting (XSS).
CVE-2023-36487
- EPSS 1.04%
- Veröffentlicht 29.06.2023 17:15:09
- Zuletzt bearbeitet 26.11.2024 20:15:22
The password reset function in ILIAS 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows remote attackers to take over the account.
CVE-2022-45918
- EPSS 1.18%
- Veröffentlicht 07.12.2022 01:15:11
- Zuletzt bearbeitet 21.11.2024 07:29:57
ILIAS before 7.16 allows External Control of File Name or Path.
CVE-2022-45917
- EPSS 1.99%
- Veröffentlicht 07.12.2022 01:15:11
- Zuletzt bearbeitet 23.04.2025 18:16:02
ILIAS before 7.16 has an Open Redirect.
CVE-2022-45916
- EPSS 0.87%
- Veröffentlicht 07.12.2022 01:15:11
- Zuletzt bearbeitet 23.04.2025 18:16:02
ILIAS before 7.16 allows XSS.
CVE-2022-45915
- EPSS 4.66%
- Veröffentlicht 07.12.2022 01:15:11
- Zuletzt bearbeitet 23.04.2025 18:16:02
ILIAS before 7.16 allows OS Command Injection.
CVE-2022-31266
- EPSS 0.82%
- Veröffentlicht 29.06.2022 01:15:07
- Zuletzt bearbeitet 20.03.2025 17:01:16
In ILIAS through 7.10, lack of verification when changing an email address (on the Profile Page) allows remote attackers to take over accounts.
CVE-2020-23996
- EPSS 2.31%
- Veröffentlicht 13.05.2021 20:15:08
- Zuletzt bearbeitet 21.11.2024 05:14:18
A local file inclusion vulnerability in ILIAS before 5.3.19, 5.4.10 and 6.0 allows remote authenticated attackers to execute arbitrary code via the import of personal data.