Impact
IliAS includes a question‑definition feature that supports image maps. In versions before 9.24, 10.12, and 11.5 the assImagemapQuestionGUI component processes the uploaded image file name and passes it directly to an ImageMagick convert command without sufficient sanitisation. The vulnerability allows a question author to embed tab‑separated ImageMagick options such as '-define pgm:format=auto' or shell commands through the file name. Because escapeshellcmd() is not applied to the entire string, an attacker can create a PHP file in the web root and achieve remote code execution. The flaw is a classic command injection (CWE‑88) that can compromise the entire web server.
Affected Systems
Vulnerable ILIAS eLearning e.V. installations running any of the following product versions are impacted: ILIAS 9.x prior to 9.24, ILIAS 10.x prior to 10.12, and ILIAS 11.x prior to 11.5. The issue resides in the ImageMap question upload functionality, notably the assImagemapQuestionGUI and related classes. Administrators or users with question‑author privileges in these installations are at risk.
Risk and Exploitability
The CVSS score of 8.7 denotes high severity, with the potential to fully compromise the system, as the attacker can execute arbitrary code on the web server. The EPSS score is not available, indicating that no public database has quantified exploitation likelihood; however, the vulnerability is in an upload feature that is accessible to privileged users, making it a feasible target for insiders or compromised author accounts. The flaw is listed outside of the CISA KEV catalog, but given its remote code execution potential, it should be treated as high priority. Successful exploitation requires control over the image upload process for a question, but no external network exposure is needed beyond normal authentication.
OpenCVE Enrichment