PT-2024-25299 · Ilias · Ilias
Daniel Schlecht
·
Published
2024-05-21
·
Updated
2024-07-03
·
CVE-2024-33529
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ILIAS versions 7.0 through 7.29
ILIAS versions 8.0 through 8.10
ILIAS version 9.0
Description
The issue allows remote authenticated attackers with administrative privileges to execute operating system commands via file uploads with dangerous types. This can be achieved by uploading files of certain types that are not properly validated, leading to potential system compromise.
Recommendations
For ILIAS versions 7.0 through 7.29, update to version 7.30 or later.
For ILIAS versions 8.0 through 8.10, update to version 8.11 or later.
For ILIAS version 9.0, consider restricting file uploads or disabling administrative privileges until a patch is available. As a temporary workaround, consider disabling the file upload feature for administrative users to minimize the risk of exploitation.
Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ilias