Remote Code Execution Vulnerability in ILIAS Certification Component
CVE-2025-11344

5.3MEDIUM

Key Information:

Vendor

ILIAS

Status
Vendor
CVE Published:
6 October 2025

What is CVE-2025-11344?

A vulnerability in the Certificate Import Handler of ILIAS could allow attackers to execute arbitrary code remotely. This issue affects versions up to 8.23, 9.13, and 10.1. Exploiting this flaw may enable unauthorized access and control over the affected systems. Users are strongly advised to upgrade to versions 8.24, 9.14, or 10.2 to mitigate this risk.

Affected Version(s)

ILIAS 8.0

ILIAS 8.1

ILIAS 8.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rehme_srlabs (VulDB User)
.
CVE-2025-11344 : Remote Code Execution Vulnerability in ILIAS Certification Component