在 ILIAS 9.24 之前版本、10.12 之前版本以及 11.5 之前版本中,存在一个不受限制的文件上传漏洞,该漏洞发生在 QTI 问题导入的图片处理过程中(具体为 模块)。此漏洞允许已认证的用户(作者)写入可执行文件。 拥有问题池导入权限的攻击者可以导入精心构造的归档文件,将 和 PHP 文件写入由 Web 服务器提供服务的图片目录,从而以 Web 服务器用户的身份实现远程代码执行(RCE)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ILIAS-eLearning e.V. | ILIAS | 5.2.8< 9.24 |
affected |
10.0< 10.12 |
affected | ||
11.0< 11.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ILIAS-eLearning e.V. | ILIAS | 5.2.8 ~ 9.24 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet