Account Takeover Vulnerability in ILIAS Product by ILIAS Inc.
CVE-2023-36487
9.8CRITICAL
What is CVE-2023-36487?
A security weakness in the password reset functionality of ILIAS versions 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows remote attackers to hijack user accounts. The vulnerability enables unauthorized users to reset passwords and gain control over accounts, emphasizing the need for immediate remediation and awareness of secure password management practices.
