Description
ILIAS Learning Management System 4.3 contains a server-side request forgery vulnerability that allows attackers to read local files through portfolio PDF export functionality. Attackers can inject a script that uses XMLHttpRequest to retrieve local file contents when the portfolio is exported to PDF.
Problem types
Server-Side Request Forgery (SSRF)
Product status
Credits
Dot/kx1z0
References
www.exploit-db.com/exploits/49148 (ExploitDB-49148)
www.ilias.de/ (ILIAS Official Vendor Homepage)
github.com/ILIAS-eLearning/ILIAS (ILIAS GitHub Repository)
www.vulncheck.com/...s/ilias-learning-management-system-ssrf (VulnCheck Advisory: ILIAS Learning Management System 4.3 - SSRF)