NA

CVE-2023-36485

Published: 25/12/2023 Updated: 14/02/2024
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

The workflow-engine of ILIAS prior to 7.23 and 8 prior to 8.3 allows remote authenticated users to run arbitrary system commands on the application server as the application user via a malicious BPMN2 workflow definition file.

Vulnerable Product Search on Vulmon Subscribe to Product

ilias ilias