Home

Description

ILIAS 7.25 (2023-09-12) allows any authenticated user to execute arbitrary operating system commands remotely, when a highly privileged account accesses an XSS payload. The injected commands are executed via the exec() function in the execQuoted() method of the ilUtil class (/Services/Utilities/classes/class.ilUtil.php) This allows attackers to inject malicious commands into the system, potentially compromising the integrity, confidentiality, and availability of the ILIAS installation and the underlying operating system.

PUBLISHED Reserved 2023-10-14 | Published 2023-10-26 | Updated 2024-09-12 | Assigner mitre




CRITICAL: 9.0CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:L/S:C/UI:R

References

rehmeinfosec.de/report/358ad5f6-f712-4f74-a5ee-476efc856cbc/

rehmeinfosec.de/labor/cve-2023-45869

rehmeinfosec.de/report/358ad5f6-f712-4f74-a5ee-476efc856cbc/

rehmeinfosec.de/labor/cve-2023-45869

cve.org (CVE-2023-45869)

nvd.nist.gov (CVE-2023-45869)

Download JSON