Remote Command Execution Vulnerability in ILIAS Software
CVE-2024-33529
7.2HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 21 May 2024
What is CVE-2024-33529?
A serious vulnerability in the ILIAS Learning Management System allows remote authenticated attackers with administrative privileges to execute arbitrary operating system commands. This can be achieved through uploading files of dangerous types, which poses a significant security risk. Effective measures should be taken to mitigate this flaw, especially in versions of ILIAS prior to 7.30, 8.11, and 9.0. It is crucial to keep software up to date and review file upload handling to prevent exploitation.
