CVE-2023-36486: High severity ilias vulnerability
Published Dec 25, 2023
·Updated
The workflow-engine of ILIAS before 7.23 and 8 before 8.3 allows remote authenticated users to run arbitrary system commands on the application server as the application user by uploading a workflow definition file with a malicious filename.
Affected Software
2 affected components
ILIAS ILIAS<7.23
ILIAS ILIAS>=8.0<8.3
Remediation
Patch Available
Patch Available
Event History
Dec 25, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Aug 26, 56091
Event
via NVD·12:16 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-36486?
CVE-2023-36486 has a high severity rating as it allows remote authenticated users to execute arbitrary system commands.
2
How do I fix CVE-2023-36486?
To fix CVE-2023-36486, upgrade ILIAS to version 7.23 or later, or to version 8.3 or later.
3
Who is affected by CVE-2023-36486?
CVE-2023-36486 affects users of ILIAS versions prior to 7.23 and between 8.0 and 8.2.
4
What is the vulnerability type of CVE-2023-36486?
CVE-2023-36486 is a remote code execution vulnerability due to improper handling of workflow definition file uploads.
5
Can CVE-2023-36486 be exploited by unauthenticated users?
No, CVE-2023-36486 requires an authenticated user to exploit the vulnerability.