CVE-2023-36487: Critical severity ILIAS ILIAS vulnerability
Published Jun 29, 2023
·Updated
The password reset function in ILIAS 7.0beta1 through 7.20 and 8.0beta1 through 8.1 allows remote attackers to take over the account.
Affected Software
2 affected components
ILIAS ILIAS>=7.0<=7.20
ILIAS ILIAS>=8.0<=8.1
Event History
Jun 29, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-36487?
The severity of CVE-2023-36487 is critical with a score of 9.8.
2
What is the affected software for CVE-2023-36487?
The affected software for CVE-2023-36487 is ILIAS versions 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1.
3
How does CVE-2023-36487 allow attackers to take over accounts?
CVE-2023-36487 allows remote attackers to take over accounts through the password reset function.
4
Is there a fix available for CVE-2023-36487?
Yes, the fix for CVE-2023-36487 is available. Please refer to the official ILIAS documentation for the fix.
5
Where can I find more information about CVE-2023-36487?
You can find more information about CVE-2023-36487 in the official ILIAS documentation.