Remote Code Execution Vulnerability in ILIAS Workflow Engine
CVE-2023-36486
7.2HIGH
What is CVE-2023-36486?
The ILIAS workflow engine versions prior to 7.23 and 8.3 are vulnerable to a remote code execution flaw which allows authenticated users to upload a specially crafted workflow definition file. This file can contain a malicious filename, enabling the execution of arbitrary system commands on the application server. This vulnerability can potentially compromise the integrity and confidentiality of the server's data and resources.
