CVE-2025-11345: ILIAS Test Import unserialize deserialization
A flaw has been found in ILIAS up to 8.23/9.13/10.1. Affected by this issue is the function unserialize of the component Test Import. This manipulation causes deserialization. It is possible to initiate the attack remotely. Upgrading to version 8.24, 9.14 and 10.2 can resolve this issue. Upgrading the affected component is advised.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11345?
CVE-2025-11345 has been rated as a critical vulnerability due to its potential for remote exploitation.
How do I fix CVE-2025-11345?
To fix CVE-2025-11345, upgrade ILIAS to version 8.24, 9.14, or 10.2.
What versions of ILIAS are affected by CVE-2025-11345?
ILIAS versions up to and including 8.23, 9.13, and 10.1 are affected by CVE-2025-11345.
Can CVE-2025-11345 be exploited remotely?
Yes, CVE-2025-11345 can be exploited remotely, which increases its risk level.
What component in ILIAS is vulnerable in CVE-2025-11345?
The vulnerable component in ILIAS is the function unserialize within the Test Import functionality.