Security-Blog

Die Security-Gruppe informiert über behobene Sicherheitslücken in ILIAS

August 2026

Tokar, David [tokard], Wolf, Fabian [fwolf] - 11. Aug 2026, 17:00

Following 10 security issues have been resolved:

0047893: Course: Add missing permission checks for Learning Objectives-Driven Courses
0048009: SOAP Authenticated arbitrary file read
0048026: Course: Unauthorized access to settings
0048067: Authenticated RCE via MediaPool
0048123: COPage: Full Path Disclosure
0048128: SQL injection in Repository Trash
0048152: Unauthenticated PHP object injection -> RCE in the Shibboleth logout endpoint
0048153: Filesystem: Enforce extraction limits in Unzip
0048156: LTI: Unauthorized access to settings
0048158: Object title removed from permission message.

· Link

Tokar, David [tokard], Wolf, Fabian [fwolf] - 11. Aug 2026, 16:30

Following 10 security issues have been resolved:

0047893: Course: Add missing permission checks for Learning Objectives-Driven Courses
0048009: SOAP Authenticated arbitrary file read
0048026: Course: Unauthorized access to settings
0048067: Authenticated RCE via MediaPool
0048123: COPage: Full Path Disclosure
0048128: SQL injection in Repository Trash
0048152: Unauthenticated PHP object injection -> RCE in the Shibboleth logout endpoint
0048153: Filesystem: Enforce extraction limits in Unzip
0048156: LTI: Unauthorized access to settings
0048158: Object title removed from permission message.

· Link

Tokar, David [tokard], Wolf, Fabian [fwolf] - 11. Aug 2026, 16:00

Following 9 security issues have been resolved:

0047893: Course: Add missing permission checks for Learning Objectives-Driven Courses
0048009: SOAP Authenticated arbitrary file read
0048026: Course: Unauthorized access to settings
0048067: Authenticated RCE via MediaPool
0048128: SQL injection in Repository Trash
0048152: Unauthenticated PHP object injection -> RCE in the Shibboleth logout endpoint
0048153: Filesystem: Enforce extraction limits in Unzip
0048156: LTI: Unauthorized access to settings
0048158: Object title removed from permission message.

· Link

July 2026

Tokar, David [tokard], Wolf, Fabian [fwolf] - 7. Jul 2026, 17:00

Following 5 security issues have been resolved:

0047800: Stored XSS via HTML attribute injection
0047834: Add RBAC check for Repository Objects
0047887: SOAP: Insecure Direct Object Reference (IDOR)
0047952: Object: Remove Information on Temp File Location from Error Message
0047954: Notes: Insufficient access checks

· Link

Tokar, David [tokard], Wolf, Fabian [fwolf] - 7. Jul 2026, 16:30

Following 5 security issues have been resolved:

0047800: Stored XSS via HTML attribute injection
0047834: Add RBAC check for Repository Objects
0047887: SOAP: Insecure Direct Object Reference (IDOR)
0047952: Object: Remove Information on Temp File Location from Error Message
0047954: Notes: Insufficient access checks

· Link