CVE-2023-36486
25.12.2023, 08:15
The workflow-engine of ILIAS before 7.23 and 8 before 8.3 allows remote authenticated users to run arbitrary system commands on the application server as the application user by uploading a workflow definition file with a malicious filename.Enginsight
| Vendor | Product | Version |
|---|---|---|
| ilias | ilias | 𝑥 < 7.23 |
| ilias | ilias | 8.0 ≤ 𝑥 < 8.3 |
𝑥
= Vulnerable software versions
References