CVE-2020-23996: High severity ilias vulnerability
Published May 13, 2021
·Updated
A local file inclusion vulnerability in ILIAS before 5.3.19, 5.4.10 and 6.0 allows remote authenticated attackers to execute arbitrary code via the import of personal data.
Affected Software
2 affected components
ILIAS ILIAS<5.3.19
ILIAS ILIAS>=5.4.0<5.4.10
Remediation
Event History
May 13, 2021
CVE Published
via MITRE·07:49 PM
Data Sourced
via MITRE·07:49 PM
Description
Frequently Asked Questions
1
What is CVE-2020-23996?
CVE-2020-23996 is a local file inclusion vulnerability in ILIAS before version 5.3.19, 5.4.10, and 6.0 that allows remote authenticated attackers to execute arbitrary code via the import of personal data.
2
How severe is CVE-2020-23996?
CVE-2020-23996 has a severity value of 8.8 (high).
3
Which versions of ILIAS are affected by CVE-2020-23996?
ILIAS versions prior to 5.3.19, 5.4.10, and 6.0 are affected by CVE-2020-23996.
4
How can I fix CVE-2020-23996?
To fix CVE-2020-23996, update your ILIAS installation to version 5.3.19, 5.4.10, or 6.0 or later.
5
Where can I find more information about CVE-2020-23996?
You can find more information about CVE-2020-23996 at the following references: [link1], [link2], [link3].