在 ILIAS 系统 9.21、10.9 和 11.2 及更早版本中发现了一个安全漏洞。该漏洞影响了“MediaPool”组件中 文件中 函数的处理逻辑。攻击者可以通过该函数触发不受限制的文件上传,且攻击可远程发起。将系统升级至 9.22、10.10 或 11.3 版本可以缓解此问题。对应的修复补丁标识为 / 。建议升级受影响的组件以消除该风险。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | ILIAS | 9.0 |
cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85138 | 7.3 HIGH | SeaCMS WeChat index.php addslashes sql injection |
| CVE-2026-85137 | 7.3 HIGH | SeaCMS Locoy Collector seacms_locoy_news.php parseIf code injection |
No comments yet