The workflow-engine of ILIAS before 7.23 and 8 before 8.3 allows remote authenticated users to run arbitrary system commands on the application server as the application user via a malicious BPMN2 workflow definition file.
The password reset function in ILIAS 7.0beta1 through 7.20 and 8.0beta1 through 8.1 allows remote attackers to take over the account.
ILIAS 7.21 and 8.0beta1 through 8.2 is vulnerable to reflected Cross-Site Scripting (XSS).
ILIAS 7.21 and 8.0beta1 through 8.2 is vulnerable to stored Cross Site Scripting (XSS).