PT-2023-8450 · Ilias · Ilias

CVE-2023-36486

·

Published

2023-12-25

·

Updated

2024-02-14

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ILIAS versions prior to 7.23 ILIAS versions 8 prior to 8.3
Description The issue is related to the incorrect implementation of the sequence of actions in the ILIAS learning management system. It allows a remote attacker to execute arbitrary system commands on the application server by uploading a workflow definition file with a malicious filename. This can be done by remote authenticated users.
Recommendations For ILIAS versions prior to 7.23, update to version 7.23 or later to resolve the issue. For ILIAS versions 8 prior to 8.3, update to version 8.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the workflow-engine feature until a patch is available. Avoid uploading workflow definition files from untrusted sources to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-00848
CVE-2023-36486

Affected Products

Ilias