Impact
This vulnerability allows an attacker to execute arbitrary code by uploading a specially crafted ZIP file to the ILIAS system. The flaw stems from insufficient validation of the uploaded file paths, enabling the construction of malicious file locations that the system processes. Successful exploitation grants the attacker full control over the affected server, potentially compromising confidentiality, integrity, and availability of all data managed by the application.
Affected Systems
ILIAS product by ILIAS is affected. The vulnerable releases are ILIAS 6.23, all 7.x versions preceding 7.22, and 8.1. Any deployment running one of these versions without an upgrade is at risk.
Risk and Exploitability
The publicly disclosed CVSS score of 3.3 indicates a low severity, yet the impact type is high. The EPSS score of 0.00223 shows a very low but non‑zero probability of exploitation, and the vulnerability is not listed in CISA KEV. The likely attack vector is a web‑based file upload endpoint. Exploitation requires the attacker to deliver a specially crafted ZIP file that the system expands to unauthorized locations, leading to code execution.
OpenCVE Enrichment