Vulnerability in ILIAS Workflow Engine Allows Unauthorized Command Execution
CVE-2023-36485
7.2HIGH
What is CVE-2023-36485?
The ILIAS workflow engine, present in versions before 7.23 and 8 before 8.3, is susceptible to a flaw that permits authenticated users to execute arbitrary system commands on the application server. This occurs via a crafted BPMN2 workflow definition file, presenting serious security concerns for users of the platform. Proper remediation is crucial to protect against this exploit.
