PT-2026-83781 · Ilias · Ilias
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ILIAS versions prior to 9.22
ILIAS versions 10.0 through 10.9
ILIAS versions 11.0 through 11.2
Description
An arbitrary file read issue exists in the SOAP
addFile() method. Authenticated users can read server files by providing crafted XML using COPY-mode imports. This is possible because an unsandboxed import directory allows the construction of absolute file paths, enabling the retrieval of sensitive data such as configuration files containing database credentials and setup passwords.Recommendations
Update ILIAS to version 9.22 or later.
Update ILIAS to version 11.0 or later (specifically versions beyond 10.9).
Update ILIAS to version 11.3 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ilias