CVE-2026-107639: ILIAS before 9.24, 10.12, and 11.5 Argument Injection via Image Map Question Upload Filename
ILIAS before 9.24, 10.x before 10.12 and 11.x before 11.5 contains an argument injection vulnerability in assImagemapQuestionGUI that allows question authors to inject ImageMagick convert options via uploaded image filenames. Attackers can embed tab-separated options, which escapeshellcmd() does not neutralise, to write a PHP file under the web root and achieve remote code execution.
Affected Software
Event History
Frequently Asked Questions
Which users could exploit this issue?
A user who can author Image Map questions and upload an image can exploit the issue. No user interaction is required after the malicious upload is processed.
What conditions are required for exploitation?
The attacker needs authenticated privileges sufficient to create or edit an Image Map question and upload an image with a crafted filename. The vulnerable image-processing path must invoke ImageMagick convert on that upload.
Are default installations affected?
The available information does not establish whether Image Map questions or the required authoring permissions are enabled by default. Exposure depends on whether users can create Image Map questions and upload images.
What is the impact of successful exploitation?
A successful attacker can inject ImageMagick convert options through tab-separated filename content, write a PHP file beneath the web root, and achieve remote code execution. This can affect confidentiality, integrity, and availability.
What can be done if upgrading is not immediately possible?
The provided information supports restricting untrusted users' ability to author Image Map questions or upload images as an interim mitigation. Review uploads associated with Image Map questions for crafted filenames containing tab-separated option content and investigate unexpected PHP files under the web root.