Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-108113— ILIAS before 9.24, 10.12, and 11.5 Unrestricted File Upload via QTI Import

Quick assessment

Affected
ILIAS-eLearning e.V. ILIAS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 ILIAS 9.24 之前版本、10.12 之前版本以及 11.5 之前版本中,存在一个不受限制的文件上传漏洞,该漏洞发生在 QTI 问题导入的图片处理过程中(具体为 模块)。此漏洞允许已认证的用户(作者)写入可执行文件。 拥有问题池导入权限的攻击者可以导入精心构造的归档文件,将 和 PHP 文件写入由 Web 服务器提供服务的图片目录,从而以 Web 服务器用户的身份实现远程代码执行(RCE)。

CVSS 8.8 · High

Affected Version Matrix 3

VendorProduct Version RangeStatus
ILIAS-eLearning e.V. ILIAS 5.2.8< 9.24 affected
10.0< 10.12 affected
11.0< 11.5 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-108113

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ILIAS before 9.24, 10.12, and 11.5 Unrestricted File Upload via QTI Import
Source: CVE Program / CVE List V5
Vulnerability Description
ILIAS before 9.24, 10.12, and 11.5 contains an unrestricted file upload vulnerability in QTI question import image handling (ilQtiMatImageSecurity) that allows authenticated authors to write executable files. Attackers with question pool import rights can import a crafted archive writing a .htaccess and PHP file to the web-served image directory, achieving remote code execution as the web server user.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
危险类型文件的不加限制上传
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ILIAS-eLearning e.V. ILIAS 5.2.8 ~ 9.24 -

II. Public POCs for CVE-2026-108113

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-108113

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-108113 (4)

Vendor Advisories for CVE-2026-108113 (1)

Security Blog Posts for CVE-2026-108113 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-108113

No comments yet


Leave a comment