ILIAS是德国ILIAS组织开源的一套学习管理系统。 ILIAS 9.22之前版本、10.10之前版本和11.3之前版本存在SQL注入漏洞,该漏洞源于HTTP请求中的表导航排序字段未经验证直接传入SQL查询的ORDER BY子句,导致具有任意容器写权限的已认证用户可通过排序参数注入任意SQL,实现完全读写数据库及管理员账户接管。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ILIAS-eLearning e.V. | ILIAS | 9.0< 9.22 |
affected |
10.0< 10.10 |
affected | ||
11.0< 11.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ILIAS-eLearning e.V. | ILIAS | 9.0 ~ 9.22 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet