Impact
The flaw lies in the uploadMultipleSubtitleFileObject function within MediaPool's ZipAdapter, enabling an attacker to upload arbitrary files without restriction. The vulnerability is an instance of improper file upload restriction and improper access control. Unchecked uploads may contain malicious content or scripts, potentially leading to further compromise of the server or hosting environment. The official description indicates that the error allows unrestricted upload and can be exploited remotely.
Affected Systems
ILIAS versions up to and including 9.21, 10.9, and 11.2 contain the flaw. The supply chain of the patch identifies commit ef5d7f99fe1ea0381db04b333a2906548b3590e4 or b0d61be43671b6bfe91baf469a5ee11e764f2e23 as the fix. Upgrading to the latest releases—9.22, 10.10, or 11.3—removes the vulnerability. No other product versions are known to be affected.
Risk and Exploitability
The CVSS score is 5.3, classifying the issue as medium severity. Because the EPSS score is unavailable, the likelihood of exploitation is unclear, yet the description notes that the attack can be launched remotely, which raises concern. The vulnerability is not listed in the CISA KEV catalog, but the unrestricted upload capability is a recognized threat vector for further attacks such as remote code execution if a malicious file type is accepted. Therefore, while the immediate risk is moderate, the potential for escalation remains if the system allows execution of uploaded content.
OpenCVE Enrichment