CVE-2023-32778
3.3
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N
Summary
An issue was discovered in ILIAS 6.23, 7 before 7.22, and 8.1. An attacker can execute arbitrary code via ZIP upload.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ILIAS | ILIAS | 6.23 | affected |
| ILIAS | ILIAS | 7 < 7.22 | affected |
| ILIAS | ILIAS | 8.1 | affected |
Weaknesses
- CWE-23: CWE-23 Relative Path Traversal
References
- https://docu.ilias.de/goto.php?target=wiki_5307&client_id=docu#secissues
- https://docu.ilias.de/goto_docu_pg_141704_35.html
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.