CVE-2023-36486

The workflow-engine of ILIAS before 7.23 and 8 before 8.3 allows remote authenticated users to run arbitrary system commands on the application server as the application user by uploading a workflow definition file with a malicious filename.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*
cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:09

Type Values Removed Values Added
References () https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui&cmdNode=xd:kx:54&cmdClass=ilBlogPostingGUI&cmd=previewFullscreen&ref_id=3439&prvm=fsc&bmn=2023-12&blpg=786 - Vendor Advisory () https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui&cmdNode=xd:kx:54&cmdClass=ilBlogPostingGUI&cmd=previewFullscreen&ref_id=3439&prvm=fsc&bmn=2023-12&blpg=786 - Vendor Advisory
References () https://github.com/ILIAS-eLearning/ILIAS/pull/5987 - Patch () https://github.com/ILIAS-eLearning/ILIAS/pull/5987 - Patch
References () https://github.com/ILIAS-eLearning/ILIAS/pull/5988 - Patch () https://github.com/ILIAS-eLearning/ILIAS/pull/5988 - Patch

14 Feb 2024, 00:22

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : 7.2

03 Jan 2024, 22:54

Type Values Removed Values Added
References () https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui&cmdNode=xd:kx:54&cmdClass=ilBlogPostingGUI&cmd=previewFullscreen&ref_id=3439&prvm=fsc&bmn=2023-12&blpg=786 - () https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui&cmdNode=xd:kx:54&cmdClass=ilBlogPostingGUI&cmd=previewFullscreen&ref_id=3439&prvm=fsc&bmn=2023-12&blpg=786 - Vendor Advisory
References () https://github.com/ILIAS-eLearning/ILIAS/pull/5987 - () https://github.com/ILIAS-eLearning/ILIAS/pull/5987 - Patch
References () https://github.com/ILIAS-eLearning/ILIAS/pull/5988 - () https://github.com/ILIAS-eLearning/ILIAS/pull/5988 - Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
First Time Ilias ilias
Ilias
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*

26 Dec 2023, 20:34

Type Values Removed Values Added
Summary
  • (es) El motor de workflow de ILIAS anterior a 7.23 y 8 anterior a 8.3 permite a usuarios remotos autenticados ejecutar comandos arbitrarios del sistema en el servidor de aplicaciones como usuario de la aplicación cargando un archivo de definición de workflow con un nombre de archivo malicioso.

25 Dec 2023, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-25 08:15

Updated : 2024-11-21 08:09


NVD link : CVE-2023-36486

Mitre link : CVE-2023-36486

CVE.ORG link : CVE-2023-36486


JSON object : View

Products Affected

ilias

  • ilias