ILIAS 5.3.10

CPE Details

ILIAS 5.3.10
5.3.10
2019-07-23 11:38 +00:00
2019-07-23 11:38 +00:00

Alerte pour un CPE

Stay informed of any changes for a specific CPE.
Alert management

CPE Name: cpe:2.3:a:ilias:ilias:5.3.10:*:*:*:*:*:*:*

Informations

Vendor

ilias

Product

ilias

Version

5.3.10

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-36485 2023-12-24 23:00 +00:00 The workflow-engine of ILIAS before 7.23 and 8 before 8.3 allows remote authenticated users to run arbitrary system commands on the application server as the application user via a malicious BPMN2 workflow definition file.
7.2
HIGH
CVE-2023-36486 2023-12-24 23:00 +00:00 The workflow-engine of ILIAS before 7.23 and 8 before 8.3 allows remote authenticated users to run arbitrary system commands on the application server as the application user by uploading a workflow definition file with a malicious filename.
7.2
HIGH
CVE-2022-45915 2022-12-06 23:00 +00:00 ILIAS before 7.16 allows OS Command Injection.
8.8
HIGH
CVE-2022-45916 2022-12-06 23:00 +00:00 ILIAS before 7.16 allows XSS.
5.4
MEDIUM
CVE-2022-45917 2022-12-06 23:00 +00:00 ILIAS before 7.16 has an Open Redirect.
6.1
MEDIUM
CVE-2022-45918 2022-12-06 23:00 +00:00 ILIAS before 7.16 allows External Control of File Name or Path.
6.5
MEDIUM
CVE-2022-31266 2022-06-28 22:46 +00:00 In ILIAS through 7.10, lack of verification when changing an email address (on the Profile Page) allows remote attackers to take over accounts.
9.8
CRITICAL
CVE-2020-23996 2021-05-13 17:49 +00:00 A local file inclusion vulnerability in ILIAS before 5.3.19, 5.4.10 and 6.0 allows remote authenticated attackers to execute arbitrary code via the import of personal data.
8.8
HIGH
CVE-2020-23995 2021-05-13 17:49 +00:00 An information disclosure vulnerability in ILIAS before 5.3.19, 5.4.12 and 6.0 allows remote authenticated attackers to get the upload data path via a workspace upload.
6.5
MEDIUM
CVE-2019-1010237 2019-07-22 12:46 +00:00 Ilias 5.3 before 5.3.12; 5.2 before 5.2.21 is affected by: Cross Site Scripting (XSS) - CWE-79 Type 2: Stored XSS (or Persistent). The impact is: Execute code in the victim's browser. The component is: Assessment / TestQuestionPool. The attack vector is: Cloze Test Text gap (attacker) / Corrections view (victim). The fixed version is: 5.3.12.
6.1
MEDIUM
Click on the button to the left (OFF), to authorize the inscription of cookie improving the functionalities of the site. Click on the button to the left (Accept all), to unauthorize the inscription of cookie improving the functionalities of the site.