Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
6.5
CVSSv3
CVE-2022-45918
Published: 07/12/2022 Updated: 09/02/2024
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0
Subscribe to Ilias
Vulnerability Summary
ILIAS prior to 7.16 allows External Control of File Name or Path.
Vulnerability Trend
Vulnerable Product
Search on Vulmon
Subscribe to Product
ilias ilias
Exploits
Exploit DB: ILIAS eLearning 7.15 Command Injection / XSS / LFI / Open Redirect
ILIAS eLearning versions 715 and below suffer from authenticated command injection, persistent cross site scripting, local file inclusion, and open redirection vulnerabilities ...
References
CWE-610
https://sec-consult.com/vulnerability-lab/advisory/multiple-critical-vulnerabilities-in-ilias-elearning-platform/
http://seclists.org/fulldisclosure/2022/Dec/7
http://packetstormsecurity.com/files/170181/ILIAS-eLearning-7.15-Command-Injection-XSS-LFI-Open-Redirect.html
https://nvd.nist.gov
https://packetstormsecurity.com/files/170181/ILIAS-eLearning-7.15-Command-Injection-XSS-LFI-Open-Redirect.html
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
SSTI
CVE-2024-35863
CVE-2024-35910
man-in-the-middle
CVE-2024-35912
CVE-2024-25742
LFI
CVE-2024-32002
CVE-2024-22120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started