CVE-2020-23995: Medium severity ilias vulnerability
Published May 13, 2021
·Updated
An information disclosure vulnerability in ILIAS before 5.3.19, 5.4.12 and 6.0 allows remote authenticated attackers to get the upload data path via a workspace upload.
Affected Software
2 affected components
ILIAS ILIAS<5.3.19
ILIAS ILIAS>=5.4.0<5.4.12
Remediation
Event History
May 13, 2021
CVE Published
via MITRE·07:49 PM
Data Sourced
via MITRE·07:49 PM
Description
Frequently Asked Questions
1
What is CVE-2020-23995?
CVE-2020-23995 is an information disclosure vulnerability in ILIAS before versions 5.3.19, 5.4.12, and 6.0 that allows remote authenticated attackers to obtain the upload data path via a workspace upload.
2
How does CVE-2020-23995 affect ILIAS?
CVE-2020-23995 affects ILIAS versions before 5.3.19, 5.4.12, and 6.0.
3
What is the severity of CVE-2020-23995?
The severity of CVE-2020-23995 is medium, with a severity value of 6.5.
4
How can I fix CVE-2020-23995?
To fix CVE-2020-23995, upgrade to ILIAS versions 5.3.19, 5.4.12, or 6.0.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-23995?
The Common Weakness Enumeration (CWE) ID for CVE-2020-23995 is CWE-209.