Directory Traversal Vulnerability in ILIAS Learning Module by ILIAS Development Team
CVE-2023-45868

8.1HIGH

Key Information:

Vendor

Ilias

Status
Vendor
CVE Published:
26 October 2023

What is CVE-2023-45868?

The Learning Module in ILIAS version 7.25 contains a directory traversal vulnerability that can be exploited by attackers with basic user privileges. This security flaw allows for the unauthorized movement of sensitive directories outside the documentRoot to publicly accessible locations using the PHP rename() function. By manipulating POST requests during exercise unit creation, attackers can change directory paths, which may lead to a total loss of confidentiality of sensitive resources and potentially disrupt access to affected components. This makes it crucial for users to apply security measures and updates promptly to safeguard their systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.