Home

Description

ILIAS Learning Management System 4.3 contains a server-side request forgery vulnerability that allows attackers to read local files through portfolio PDF export functionality. Attackers can inject a script that uses XMLHttpRequest to retrieve local file contents when the portfolio is exported to PDF.

PUBLISHED Reserved 2026-01-25 | Published 2026-01-28 | Updated 2026-01-29 | Assigner VulnCheck




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L
MEDIUM: 4.0CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Problem types

Server-Side Request Forgery (SSRF)

Product status

4.3-5.1
affected

Credits

Dot/kx1z0 finder

References

www.exploit-db.com/exploits/49148 (ExploitDB-49148) exploit

www.ilias.de/ (ILIAS Official Vendor Homepage) product

github.com/ILIAS-eLearning/ILIAS (ILIAS GitHub Repository) product

www.vulncheck.com/...s/ilias-learning-management-system-ssrf (VulnCheck Advisory: ILIAS Learning Management System 4.3 - SSRF) third-party-advisory

cve.org (CVE-2020-36944)

nvd.nist.gov (CVE-2020-36944)

Download JSON