📦 Ilias

by Ilias

🔍 What is Ilias?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-45869

CRITICAL CVSS 9.0 Oct 26, 2023

This vulnerability allows any authenticated ILIAS user to execute arbitrary operating system commands when a privileged administrator account interacts with a crafted XSS payload. The attack combines ...

CVE-2023-36487

CRITICAL CVSS 9.8 Jun 29, 2023

CVE-2023-36487 is a critical authentication bypass vulnerability in ILIAS learning management system that allows remote attackers to take over user accounts via the password reset function. Attackers ...

CVE-2024-33529

HIGH CVSS 7.2 May 21, 2024

This vulnerability allows authenticated administrators in ILIAS e-learning platforms to execute arbitrary operating system commands by uploading files with dangerous file types. It affects ILIAS versi...

CVE-2024-33526

HIGH CVSS 7.1 May 21, 2024

A stored cross-site scripting (XSS) vulnerability in ILIAS e-learning LMS allows authenticated administrators to inject malicious scripts via XML file uploads in user role import functionality. This a...

CVE-2023-36486

HIGH CVSS 7.2 Dec 25, 2023

This vulnerability allows remote authenticated users to execute arbitrary system commands on the ILIAS application server by uploading a workflow definition file with a malicious filename. The attacke...

CVE-2023-45868

HIGH CVSS 8.1 Oct 26, 2023

CVE-2023-45868 is a directory traversal vulnerability in ILIAS Learning Module 7.25 that allows authenticated attackers to relocate directories outside the document root to publicly accessible locatio...

CVE-2020-23996

HIGH CVSS 8.8 May 13, 2021

CVE-2020-23996 is a local file inclusion vulnerability in ILIAS e-learning platforms that allows remote authenticated attackers to execute arbitrary code by importing malicious personal data. This aff...

CVE-2025-11346

MEDIUM CVSS 6.3 Oct 6, 2025

This CVE describes a remote deserialization vulnerability in ILIAS learning management systems. Attackers can exploit the Base64 Decoding Handler's unserialize function by manipulating the f_settings ...

CVE-2025-11344

MEDIUM CVSS 6.3 Oct 6, 2025

This vulnerability in ILIAS learning management system allows remote attackers to execute arbitrary code through the Certificate Import Handler component. It affects ILIAS installations up to versions...

CVE-2024-33528

MEDIUM CVSS 4.7 May 21, 2024

A stored cross-site scripting (XSS) vulnerability in ILIAS eLearning LMS allows authenticated users with tutor privileges to inject malicious scripts via XML file upload. This can lead to session hija...