CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
The workflow-engine of ILIAS before 7.23 and 8 before 8.3 allows remote authenticated users to run arbitrary system commands on the application server as the application user via a malicious BPMN2 workflow definition file. | 7.2 |
High |
||
The workflow-engine of ILIAS before 7.23 and 8 before 8.3 allows remote authenticated users to run arbitrary system commands on the application server as the application user by uploading a workflow definition file with a malicious filename. | 7.2 |
High |
||
ILIAS before 7.16 allows OS Command Injection. | 8.8 |
High |
||
ILIAS before 7.16 allows XSS. | 5.4 |
Medium |
||
ILIAS before 7.16 has an Open Redirect. | 6.1 |
Medium |
||
ILIAS before 7.16 allows External Control of File Name or Path. | 6.5 |
Medium |
||
In ILIAS through 7.10, lack of verification when changing an email address (on the Profile Page) allows remote attackers to take over accounts. | 4.3 |
Medium |
||
A local file inclusion vulnerability in ILIAS before 5.3.19, 5.4.10 and 6.0 allows remote authenticated attackers to execute arbitrary code via the import of personal data. | 8.8 |
High |
||
An information disclosure vulnerability in ILIAS before 5.3.19, 5.4.12 and 6.0 allows remote authenticated attackers to get the upload data path via a workspace upload. | 6.5 |
Medium |
||
ILIAS before 5.1.26, 5.2.x before 5.2.15, and 5.3.x before 5.3.4, due to inconsistencies in parameter handling, is vulnerable to various instances of reflected cross-site-scripting. | 6.1 |
Medium |
||
ILIAS before 5.2.4 has XSS via the cmd parameter to the displayHeader function in setup/classes/class.ilSetupGUI.php in the Setup component. | 6.1 |
Medium |
||
Stored XSS vulnerability in the Media Objects component of ILIAS before 5.1.21 and 5.2.x before 5.2.9 allows an authenticated user to inject JavaScript to gain administrator privileges, related to the setParameter function in Services/MediaObjects/classes/class.ilMediaItem.php. | 5.4 |
Medium |
||
ILIAS before 5.2.3 has XSS via SVG documents. | 6.1 |
Medium |