Directory Traversal Vulnerability in ILIAS by ILIAS Open Source
CVE-2023-45867
6.5MEDIUM
What is CVE-2023-45867?
The ILIAS platform, specifically the ScormAicc module in the 2013-09-12 release, is susceptible to a directory traversal vulnerability. This flaw enables attackers with privileged accounts, like those in the tutor role, to manipulate URL parameters for unauthorized file access. By inserting directory traversal sequences, an attacker can retrieve sensitive files that the web server user, www-data, can read, including potentially critical configuration files outside the document root. The exploitation of this vulnerability can lead to the exposure of sensitive information, significantly compromising the confidentiality of the system.
