Ilias
Products
2- 44 CVEs
- 2 CVEs
Recent CVEs
45| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-36487 | Cri | 0.64 | 9.8 | 0.01 | Jun 29, 2023 | The password reset function in ILIAS 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows remote attackers to take over the account. | ||
| CVE-2023-45869 | Cri | 0.59 | 9.0 | 0.01 | Oct 26, 2023 | ILIAS 7.25 (2023-09-12) allows any authenticated user to execute arbitrary operating system commands remotely, when a highly privileged account accesses an XSS payload. The injected commands are executed via the exec() function in the execQuoted() method of the ilUtil class… | ||
| CVE-2022-45915 | Hig | 0.58 | 8.8 | 0.05 | Dec 7, 2022 | ILIAS before 7.16 allows OS Command Injection. | ||
| CVE-2020-25268 | Hig | 0.57 | 8.8 | 0.02 | Nov 10, 2020 | Remote Code Execution can occur via the external news feed in ILIAS 6.4 because of incorrect parameter sanitization for Magpie RSS data. | ||
| CVE-2023-45868 | Hig | 0.53 | 8.1 | 0.01 | Oct 26, 2023 | The Learning Module in ILIAS 7.25 (2023-09-12 release) allows an attacker (with basic user privileges) to achieve a high-impact Directory Traversal attack on confidentiality and availability. By exploiting this network-based vulnerability, the attacker can move specified… | ||
| CVE-2024-33529 | Hig | 0.47 | 7.2 | 0.01 | May 21, 2024 | ILIAS 7 before 7.30 and ILIAS 8 before 8.11 as well as ILIAS 9.0 allow remote authenticated attackers with administrative privileges to execute operating system commands via file uploads with dangerous types. | ||
| CVE-2024-33526 | Hig | 0.46 | 7.1 | 0.01 | May 21, 2024 | A Stored Cross-site Scripting (XSS) vulnerability in the "Import of user role and title of user role" feature in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers with administrative privileges to inject arbitrary web script or HTML via XML file… | ||
| CVE-2023-45867 | Med | 0.42 | 6.5 | 0.01 | Oct 26, 2023 | ILIAS (2013-09-12 release) contains a medium-criticality Directory Traversal local file inclusion vulnerability in the ScormAicc module. An attacker with a privileged account, typically holding the tutor role, can exploit this to gain unauthorized access to and potentially… | ||
| CVE-2025-11346 | Med | 0.41 | 6.3 | 0.00 | Oct 6, 2025 | A vulnerability has been found in ILIAS up to 8.23/9.13/10.1. This affects the function unserialize of the component Base64 Decoding Handler. Such manipulation of the argument f_settings leads to deserialization. It is possible to launch the attack remotely. Upgrading to version… | ||
| CVE-2025-11344 | Med | 0.41 | 6.3 | 0.00 | Oct 6, 2025 | A vulnerability was detected in ILIAS up to 8.23/9.13/10.1. Affected by this vulnerability is an unknown functionality of the component Certificate Import Handler. The manipulation results in Remote Code Execution. The attack may be performed from remote. Upgrading to version… | ||
| CVE-2023-36484 | Med | 0.40 | 6.1 | 0.00 | Jun 29, 2023 | ILIAS 7.21 and 8.0_beta1 through 8.2 is vulnerable to reflected Cross-Site Scripting (XSS). | ||
| CVE-2022-45917 | Med | 0.40 | 6.1 | 0.02 | Dec 7, 2022 | ILIAS before 7.16 has an Open Redirect. | ||
| CVE-2017-7583 | Med | 0.40 | 6.1 | 0.01 | Apr 7, 2017 | ILIAS before 5.2.3 has XSS via SVG documents. | ||
| CVE-2025-11345 | Med | 0.36 | 5.5 | 0.00 | Oct 6, 2025 | A flaw has been found in ILIAS up to 8.23/9.13/10.1. Affected by this issue is the function unserialize of the component Test Import. This manipulation causes deserialization. It is possible to initiate the attack remotely. Upgrading to version 8.24, 9.14 and 10.2 can resolve… | ||
| CVE-2024-33527 | Med | 0.35 | 5.4 | 0.00 | May 21, 2024 | A Stored Cross-site Scripting (XSS) vulnerability in the "Import of Users and login name of user" feature in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers with administrative privileges to inject arbitrary web script or HTML via XML file… | ||
| CVE-2023-36488 | Med | 0.35 | 5.4 | 0.00 | Jun 29, 2023 | ILIAS 7.21 and 8.0_beta1 through 8.2 is vulnerable to stored Cross Site Scripting (XSS). | ||
| CVE-2022-45918 | Med | 0.35 | 6.5 | 0.01 | Dec 7, 2022 | ILIAS before 7.16 allows External Control of File Name or Path. | ||
| CVE-2022-45916 | Med | 0.35 | 5.4 | 0.01 | Dec 7, 2022 | ILIAS before 7.16 allows XSS. | ||
| CVE-2020-25267 | Med | 0.35 | 5.4 | 0.01 | Nov 10, 2020 | An XSS issue exists in the question-pool file-upload preview feature in ILIAS 6.4. | ||
| CVE-2017-15538 | Med | 0.35 | 5.4 | 0.01 | Oct 17, 2017 | Stored XSS vulnerability in the Media Objects component of ILIAS before 5.1.21 and 5.2.x before 5.2.9 allows an authenticated user to inject JavaScript to gain administrator privileges, related to the setParameter function in Services/MediaObjects/classes/class.ilMediaItem.php. |
- risk 0.64cvss 9.8epss 0.01
The password reset function in ILIAS 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows remote attackers to take over the account.
- risk 0.59cvss 9.0epss 0.01
ILIAS 7.25 (2023-09-12) allows any authenticated user to execute arbitrary operating system commands remotely, when a highly privileged account accesses an XSS payload. The injected commands are executed via the exec() function in the execQuoted() method of the ilUtil class…
- risk 0.58cvss 8.8epss 0.05
ILIAS before 7.16 allows OS Command Injection.
- risk 0.57cvss 8.8epss 0.02
Remote Code Execution can occur via the external news feed in ILIAS 6.4 because of incorrect parameter sanitization for Magpie RSS data.
- risk 0.53cvss 8.1epss 0.01
The Learning Module in ILIAS 7.25 (2023-09-12 release) allows an attacker (with basic user privileges) to achieve a high-impact Directory Traversal attack on confidentiality and availability. By exploiting this network-based vulnerability, the attacker can move specified…
- risk 0.47cvss 7.2epss 0.01
ILIAS 7 before 7.30 and ILIAS 8 before 8.11 as well as ILIAS 9.0 allow remote authenticated attackers with administrative privileges to execute operating system commands via file uploads with dangerous types.
- risk 0.46cvss 7.1epss 0.01
A Stored Cross-site Scripting (XSS) vulnerability in the "Import of user role and title of user role" feature in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers with administrative privileges to inject arbitrary web script or HTML via XML file…
- risk 0.42cvss 6.5epss 0.01
ILIAS (2013-09-12 release) contains a medium-criticality Directory Traversal local file inclusion vulnerability in the ScormAicc module. An attacker with a privileged account, typically holding the tutor role, can exploit this to gain unauthorized access to and potentially…
- risk 0.41cvss 6.3epss 0.00
A vulnerability has been found in ILIAS up to 8.23/9.13/10.1. This affects the function unserialize of the component Base64 Decoding Handler. Such manipulation of the argument f_settings leads to deserialization. It is possible to launch the attack remotely. Upgrading to version…
- risk 0.41cvss 6.3epss 0.00
A vulnerability was detected in ILIAS up to 8.23/9.13/10.1. Affected by this vulnerability is an unknown functionality of the component Certificate Import Handler. The manipulation results in Remote Code Execution. The attack may be performed from remote. Upgrading to version…
- risk 0.40cvss 6.1epss 0.00
ILIAS 7.21 and 8.0_beta1 through 8.2 is vulnerable to reflected Cross-Site Scripting (XSS).
- risk 0.40cvss 6.1epss 0.02
ILIAS before 7.16 has an Open Redirect.
- risk 0.40cvss 6.1epss 0.01
ILIAS before 5.2.3 has XSS via SVG documents.
- risk 0.36cvss 5.5epss 0.00
A flaw has been found in ILIAS up to 8.23/9.13/10.1. Affected by this issue is the function unserialize of the component Test Import. This manipulation causes deserialization. It is possible to initiate the attack remotely. Upgrading to version 8.24, 9.14 and 10.2 can resolve…
- risk 0.35cvss 5.4epss 0.00
A Stored Cross-site Scripting (XSS) vulnerability in the "Import of Users and login name of user" feature in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers with administrative privileges to inject arbitrary web script or HTML via XML file…
- risk 0.35cvss 5.4epss 0.00
ILIAS 7.21 and 8.0_beta1 through 8.2 is vulnerable to stored Cross Site Scripting (XSS).
- risk 0.35cvss 6.5epss 0.01
ILIAS before 7.16 allows External Control of File Name or Path.
- risk 0.35cvss 5.4epss 0.01
ILIAS before 7.16 allows XSS.
- risk 0.35cvss 5.4epss 0.01
An XSS issue exists in the question-pool file-upload preview feature in ILIAS 6.4.
- risk 0.35cvss 5.4epss 0.01
Stored XSS vulnerability in the Media Objects component of ILIAS before 5.1.21 and 5.2.x before 5.2.9 allows an authenticated user to inject JavaScript to gain administrator privileges, related to the setParameter function in Services/MediaObjects/classes/class.ilMediaItem.php.