PT-2025-40943 · Ilias · Ilias

·

CVE-2025-11346

·

Published

2025-10-06

·

Updated

2025-10-06

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ILIAS versions prior to 8.24 ILIAS versions prior to 9.14 ILIAS versions prior to 10.2
Description A flaw exists in ILIAS related to the unserialize function within the Base64 Decoding Handler component. Manipulation of the f settings argument can lead to deserialization, potentially allowing remote attackers to exploit the system.
Recommendations Upgrade to ILIAS version 8.24 or later. Upgrade to ILIAS version 9.14 or later. Upgrade to ILIAS version 10.2 or later.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-11346

Affected Products

Ilias