CVE-2020-25268: High severity ilias vulnerability
Published Nov 10, 2020
·Updated
Remote Code Execution can occur via the external news feed in ILIAS 6.4 because of incorrect parameter sanitization for Magpie RSS data.
Affected Software
1 affected component
ILIAS ILIAS=6.4.0
Event History
Nov 10, 2020
CVE Published
via MITRE·09:46 PM
Data Sourced
via MITRE·09:46 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this ILIAS vulnerability?
The vulnerability ID for this ILIAS vulnerability is CVE-2020-25268.
2
What is the severity of CVE-2020-25268?
CVE-2020-25268 has a severity level of 8.8 (high).
3
How does the remote code execution occur in ILIAS 6.4?
Remote code execution can occur via the external news feed in ILIAS 6.4 due to incorrect parameter sanitization for Magpie RSS data.
4
Which version of ILIAS is affected by this vulnerability?
ILIAS version 6.4.0 is affected by this vulnerability.
5
Is there any fix available for CVE-2020-25268?
To fix CVE-2020-25268, it is recommended to update to a version of ILIAS that includes the necessary security patches.