ILIAS 7.25 (2023-09-12) allows any authenticated user to execute arbitrary operating system commands remotely, when a highly privileged account accesses an XSS payload. The injected commands are executed via the exec() function in the execQuoted() method of the ilUtil class (/Services/Utilities/classes/class.ilUtil.php) This allows attackers to inject malicious commands into the system, potentially compromising the integrity, confidentiality, and availability of the ILIAS installation and the underlying operating system.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-50135 ILIAS 7.25 (2023-09-12) allows any authenticated user to execute arbitrary operating system commands remotely, when a highly privileged account accesses an XSS payload. The injected commands are executed via the exec() function in the execQuoted() method of the ilUtil class (/Services/Utilities/classes/class.ilUtil.php) This allows attackers to inject malicious commands into the system, potentially compromising the integrity, confidentiality, and availability of the ILIAS installation and the underlying operating system.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-12T20:46:22.287Z

Reserved: 2023-10-14T00:00:00

Link: CVE-2023-45869

cve-icon Vulnrichment

Updated: 2024-08-02T20:29:32.584Z

cve-icon NVD

Status : Modified

Published: 2023-10-26T15:15:09.010

Modified: 2024-11-21T08:27:31.547

Link: CVE-2023-45869

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.