CVE-2023-36486
25.12.2023, 08:15
The workflow-engine of ILIAS before 7.23 and 8 before 8.3 allows remote authenticated users to run arbitrary system commands on the application server as the application user by uploading a workflow definition file with a malicious filename.Enginsight
Vendor | Product | Version |
---|---|---|
ilias | ilias | 𝑥 < 7.23 |
ilias | ilias | 8.0 ≤ 𝑥 < 8.3 |
𝑥
= Vulnerable software versions
References