PT-2023-8450 · Ilias · Ilias
Published
2023-12-25
·
Updated
2024-02-14
·
CVE-2023-36486
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ILIAS versions prior to 7.23
ILIAS versions 8 prior to 8.3
Description
The issue is related to the incorrect implementation of the sequence of actions in the ILIAS learning management system. It allows a remote attacker to execute arbitrary system commands on the application server by uploading a workflow definition file with a malicious filename. This can be done by remote authenticated users.
Recommendations
For ILIAS versions prior to 7.23, update to version 7.23 or later to resolve the issue.
For ILIAS versions 8 prior to 8.3, update to version 8.3 or later to resolve the issue.
As a temporary workaround, consider restricting access to the workflow-engine feature until a patch is available. Avoid uploading workflow definition files from untrusted sources to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ilias