Impact
The vulnerability is in ILIAS Learning Management System version 11.0 and affects the ilTrQuery::executeQueries function in the Learning Progress Tracking component. By manipulating the troup_table_nav argument, an attacker can inject arbitrary SQL statements into the LMS database, enabling remote exploitation. The attack vector is remote, and the exploit is publicly available. This issue was independently identified and fixed internally by the vendor's own security team ahead of this advisory. The flaw corresponds to CWE‑89 (SQL Injection) and CWE‑74 (Improper Neutralization of Special Elements used in Shell Commands).
Affected Systems
Affected installations are ILIAS Learning Management System version 11.0. The vulnerable executeQueries method is part of the Learning Progress Tracking component, and users of version 11.0 should verify whether their deployment includes this component and are therefore susceptible to the flaw.
Risk and Exploitability
The CVSS score is 5.1, indicating moderate severity. The EPSS score is less than 1%, indicating a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is remote, involving crafted requests to the Tracking module, and no special authentication is required beyond access to the LMS web interface.
OpenCVE Enrichment