Vulnerabilities
Vulnerable Software
Ilias:  Security Vulnerabilities
The password reset function in ILIAS 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows remote attackers to take over the account.
CVSS Score
9.8
EPSS Score
0.004
Published
2023-06-29
ILIAS 7.21 and 8.0_beta1 through 8.2 is vulnerable to stored Cross Site Scripting (XSS).
CVSS Score
5.4
EPSS Score
0.001
Published
2023-06-29
ILIAS before 7.16 allows OS Command Injection.
CVSS Score
8.8
EPSS Score
0.097
Published
2022-12-07
ILIAS before 7.16 allows XSS.
CVSS Score
5.4
EPSS Score
0.012
Published
2022-12-07
ILIAS before 7.16 has an Open Redirect.
CVSS Score
6.1
EPSS Score
0.296
Published
2022-12-07
ILIAS before 7.16 allows External Control of File Name or Path.
CVSS Score
6.5
EPSS Score
0.005
Published
2022-12-07
In ILIAS through 7.10, lack of verification when changing an email address (on the Profile Page) allows remote attackers to take over accounts.
CVSS Score
4.3
EPSS Score
0.003
Published
2022-06-29
An information disclosure vulnerability in ILIAS before 5.3.19, 5.4.12 and 6.0 allows remote authenticated attackers to get the upload data path via a workspace upload.
CVSS Score
6.5
EPSS Score
0.004
Published
2021-05-13
A local file inclusion vulnerability in ILIAS before 5.3.19, 5.4.10 and 6.0 allows remote authenticated attackers to execute arbitrary code via the import of personal data.
CVSS Score
8.8
EPSS Score
0.033
Published
2021-05-13
An XSS issue exists in the question-pool file-upload preview feature in ILIAS 6.4.
CVSS Score
5.4
EPSS Score
0.002
Published
2020-11-10


Contact Us

Shodan ® - All rights reserved