CVE-2020-36944: ILIAS Learning Management System 4.3 - SSRF
ILIAS Learning Management System 4.3 contains a server-side request forgery vulnerability that allows attackers to read local files through portfolio PDF export functionality. Attackers can inject a script that uses XMLHttpRequest to retrieve local file contents when the portfolio is exported to PDF.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36944?
CVE-2020-36944 has been classified as a medium severity vulnerability due to its potential to expose local files through SSRF.
How do I fix CVE-2020-36944?
To fix CVE-2020-36944, it is recommended to upgrade to the latest version of ILIAS Learning Management System that addresses this vulnerability.
What type of vulnerability is CVE-2020-36944?
CVE-2020-36944 is a server-side request forgery (SSRF) vulnerability.
What can attackers do with CVE-2020-36944?
Attackers can exploit CVE-2020-36944 to read local files via the portfolio PDF export functionality.
Which version of ILIAS is affected by CVE-2020-36944?
CVE-2020-36944 specifically affects ILIAS Learning Management System version 4.3.