CVE-2020-36944
EUVD-2020-3089028.01.2026, 18:16
ILIAS Learning Management System 4.3 contains a server-side request forgery vulnerability that allows attackers to read local files through portfolio PDF export functionality. Attackers can inject a script that uses XMLHttpRequest to retrieve local file contents when the portfolio is exported to PDF.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| ilias | ilias | 4.3.0 ≤ 𝑥 ≤ 5.1.0 |
𝑥
= Vulnerable software versions