Ilias
by Ilias
Source repositories
CVEs (50)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-36487 | Cri | 0.64 | 9.8 | 0.01 | Jun 29, 2023 | The password reset function in ILIAS 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows remote attackers to take over the account. | ||
| CVE-2023-45869 | Cri | 0.59 | 9.0 | 0.01 | Oct 26, 2023 | ILIAS 7.25 (2023-09-12) allows any authenticated user to execute arbitrary operating system commands remotely, when a highly privileged account accesses an XSS payload. The injected commands are executed via the exec() function in the execQuoted() method of the ilUtil class… | ||
| CVE-2022-45915 | Hig | 0.58 | 8.8 | 0.05 | Dec 7, 2022 | ILIAS before 7.16 allows OS Command Injection. | ||
| CVE-2026-80428 | Cri | 0.57 | 9.8 | 0.02 | Aug 26, 2026 | ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting serialized objects through the LTI authentication endpoint and triggering deserialization via… | ||
| CVE-2020-25268 | Hig | 0.57 | 8.8 | 0.02 | Nov 10, 2020 | Remote Code Execution can occur via the external news feed in ILIAS 6.4 because of incorrect parameter sanitization for Magpie RSS data. | ||
| CVE-2023-45868 | Hig | 0.53 | 8.1 | 0.01 | Oct 26, 2023 | The Learning Module in ILIAS 7.25 (2023-09-12 release) allows an attacker (with basic user privileges) to achieve a high-impact Directory Traversal attack on confidentiality and availability. By exploiting this network-based vulnerability, the attacker can move specified… | ||
| CVE-2026-82538 | Hig | 0.50 | 8.8 | 0.00 | Sep 4, 2026 | ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table where the table navigation sort field from HTTP requests is passed directly into the ORDER BY clause of a SQL query without validation against declared sortable… | ||
| CVE-2024-33529 | Hig | 0.47 | 7.2 | 0.01 | May 21, 2024 | ILIAS 7 before 7.30 and ILIAS 8 before 8.11 as well as ILIAS 9.0 allow remote authenticated attackers with administrative privileges to execute operating system commands via file uploads with dangerous types. | ||
| CVE-2024-33526 | Hig | 0.46 | 7.1 | 0.01 | May 21, 2024 | A Stored Cross-site Scripting (XSS) vulnerability in the "Import of user role and title of user role" feature in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers with administrative privileges to inject arbitrary web script or HTML via XML file… | ||
| CVE-2023-45867 | Med | 0.42 | 6.5 | 0.01 | Oct 26, 2023 | ILIAS (2013-09-12 release) contains a medium-criticality Directory Traversal local file inclusion vulnerability in the ScormAicc module. An attacker with a privileged account, typically holding the tutor role, can exploit this to gain unauthorized access to and potentially… | ||
| CVE-2025-11346 | Med | 0.41 | 6.3 | 0.00 | Oct 6, 2025 | A vulnerability has been found in ILIAS up to 8.23/9.13/10.1. This affects the function unserialize of the component Base64 Decoding Handler. Such manipulation of the argument f_settings leads to deserialization. It is possible to launch the attack remotely. Upgrading to version… | ||
| CVE-2025-11344 | Med | 0.41 | 6.3 | 0.01 | Oct 6, 2025 | A vulnerability was detected in ILIAS up to 8.23/9.13/10.1. Affected by this vulnerability is an unknown functionality of the component Certificate Import Handler. The manipulation results in Remote Code Execution. The attack may be performed from remote. Upgrading to version… | ||
| CVE-2023-36484 | Med | 0.40 | 6.1 | 0.00 | Jun 29, 2023 | ILIAS 7.21 and 8.0_beta1 through 8.2 is vulnerable to reflected Cross-Site Scripting (XSS). | ||
| CVE-2022-45917 | Med | 0.40 | 6.1 | 0.02 | Dec 7, 2022 | ILIAS before 7.16 has an Open Redirect. | ||
| CVE-2017-7583 | Med | 0.40 | 6.1 | 0.01 | Apr 7, 2017 | ILIAS before 5.2.3 has XSS via SVG documents. | ||
| CVE-2025-11345 | Med | 0.36 | 5.5 | 0.00 | Oct 6, 2025 | A flaw has been found in ILIAS up to 8.23/9.13/10.1. Affected by this issue is the function unserialize of the component Test Import. This manipulation causes deserialization. It is possible to initiate the attack remotely. Upgrading to version 8.24, 9.14 and 10.2 can resolve… | ||
| CVE-2026-82877 | Med | 0.35 | 6.5 | 0.00 | Aug 31, 2026 | ILIAS before versions 9.22, 10.10, and 11.3 contains an arbitrary file read vulnerability in the SOAP addFile method that allows authenticated users to read server files by supplying crafted XML with COPY-mode imports. Attackers can construct absolute file paths through an… | ||
| CVE-2024-33527 | Med | 0.35 | 5.4 | 0.00 | May 21, 2024 | A Stored Cross-site Scripting (XSS) vulnerability in the "Import of Users and login name of user" feature in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers with administrative privileges to inject arbitrary web script or HTML via XML file… | ||
| CVE-2023-36488 | Med | 0.35 | 5.4 | 0.00 | Jun 29, 2023 | ILIAS 7.21 and 8.0_beta1 through 8.2 is vulnerable to stored Cross Site Scripting (XSS). | ||
| CVE-2022-45918 | Med | 0.35 | 6.5 | 0.01 | Dec 7, 2022 | ILIAS before 7.16 allows External Control of File Name or Path. |
- risk 0.64cvss 9.8epss 0.01
The password reset function in ILIAS 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows remote attackers to take over the account.
- risk 0.59cvss 9.0epss 0.01
ILIAS 7.25 (2023-09-12) allows any authenticated user to execute arbitrary operating system commands remotely, when a highly privileged account accesses an XSS payload. The injected commands are executed via the exec() function in the execQuoted() method of the ilUtil class…
- risk 0.58cvss 8.8epss 0.05
ILIAS before 7.16 allows OS Command Injection.
- risk 0.57cvss 9.8epss 0.02
ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting serialized objects through the LTI authentication endpoint and triggering deserialization via…
- risk 0.57cvss 8.8epss 0.02
Remote Code Execution can occur via the external news feed in ILIAS 6.4 because of incorrect parameter sanitization for Magpie RSS data.
- risk 0.53cvss 8.1epss 0.01
The Learning Module in ILIAS 7.25 (2023-09-12 release) allows an attacker (with basic user privileges) to achieve a high-impact Directory Traversal attack on confidentiality and availability. By exploiting this network-based vulnerability, the attacker can move specified…
- risk 0.50cvss 8.8epss 0.00
ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table where the table navigation sort field from HTTP requests is passed directly into the ORDER BY clause of a SQL query without validation against declared sortable…
- risk 0.47cvss 7.2epss 0.01
ILIAS 7 before 7.30 and ILIAS 8 before 8.11 as well as ILIAS 9.0 allow remote authenticated attackers with administrative privileges to execute operating system commands via file uploads with dangerous types.
- risk 0.46cvss 7.1epss 0.01
A Stored Cross-site Scripting (XSS) vulnerability in the "Import of user role and title of user role" feature in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers with administrative privileges to inject arbitrary web script or HTML via XML file…
- risk 0.42cvss 6.5epss 0.01
ILIAS (2013-09-12 release) contains a medium-criticality Directory Traversal local file inclusion vulnerability in the ScormAicc module. An attacker with a privileged account, typically holding the tutor role, can exploit this to gain unauthorized access to and potentially…
- risk 0.41cvss 6.3epss 0.00
A vulnerability has been found in ILIAS up to 8.23/9.13/10.1. This affects the function unserialize of the component Base64 Decoding Handler. Such manipulation of the argument f_settings leads to deserialization. It is possible to launch the attack remotely. Upgrading to version…
- risk 0.41cvss 6.3epss 0.01
A vulnerability was detected in ILIAS up to 8.23/9.13/10.1. Affected by this vulnerability is an unknown functionality of the component Certificate Import Handler. The manipulation results in Remote Code Execution. The attack may be performed from remote. Upgrading to version…
- risk 0.40cvss 6.1epss 0.00
ILIAS 7.21 and 8.0_beta1 through 8.2 is vulnerable to reflected Cross-Site Scripting (XSS).
- risk 0.40cvss 6.1epss 0.02
ILIAS before 7.16 has an Open Redirect.
- risk 0.40cvss 6.1epss 0.01
ILIAS before 5.2.3 has XSS via SVG documents.
- risk 0.36cvss 5.5epss 0.00
A flaw has been found in ILIAS up to 8.23/9.13/10.1. Affected by this issue is the function unserialize of the component Test Import. This manipulation causes deserialization. It is possible to initiate the attack remotely. Upgrading to version 8.24, 9.14 and 10.2 can resolve…
- risk 0.35cvss 6.5epss 0.00
ILIAS before versions 9.22, 10.10, and 11.3 contains an arbitrary file read vulnerability in the SOAP addFile method that allows authenticated users to read server files by supplying crafted XML with COPY-mode imports. Attackers can construct absolute file paths through an…
- risk 0.35cvss 5.4epss 0.00
A Stored Cross-site Scripting (XSS) vulnerability in the "Import of Users and login name of user" feature in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers with administrative privileges to inject arbitrary web script or HTML via XML file…
- risk 0.35cvss 5.4epss 0.00
ILIAS 7.21 and 8.0_beta1 through 8.2 is vulnerable to stored Cross Site Scripting (XSS).
- risk 0.35cvss 6.5epss 0.01
ILIAS before 7.16 allows External Control of File Name or Path.
Page 1 of 3