Directory Traversal Vulnerability in ILIAS by ILIAS Open Source
CVE-2023-45867

6.5MEDIUM

Key Information:

Vendor

Ilias

Status
Vendor
CVE Published:
26 October 2023

What is CVE-2023-45867?

The ILIAS platform, specifically the ScormAicc module in the 2013-09-12 release, is susceptible to a directory traversal vulnerability. This flaw enables attackers with privileged accounts, like those in the tutor role, to manipulate URL parameters for unauthorized file access. By inserting directory traversal sequences, an attacker can retrieve sensitive files that the web server user, www-data, can read, including potentially critical configuration files outside the document root. The exploitation of this vulnerability can lead to the exposure of sensitive information, significantly compromising the confidentiality of the system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.