CVE-2023-36486
EUVD-2023-4043525.12.2023, 08:15
The workflow-engine of ILIAS before 7.23 and 8 before 8.3 allows remote authenticated users to run arbitrary system commands on the application server as the application user by uploading a workflow definition file with a malicious filename.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| ilias | ilias | 𝑥 < 7.23 |
| ilias | ilias | 8.0 ≤ 𝑥 < 8.3 |
𝑥
= Vulnerable software versions
References