Security-Blog
ILIAS 10.10
Following 10 security issues have been resolved:
0047893: Course: Add missing permission checks for Learning Objectives-Driven Courses
0048009: SOAP Authenticated arbitrary file read
0048026: Course: Unauthorized access to settings
0048067: Authenticated RCE via MediaPool
0048123: COPage: Full Path Disclosure
0048128: SQL injection in Repository Trash
0048152: Unauthenticated PHP object injection -> RCE in the Shibboleth logout endpoint
0048153: Filesystem: Enforce extraction limits in Unzip
0048156: LTI: Unauthorized access to settings
0048158: Object title removed from permission message.
Affected Version(s) | 9.21, 10.9, 11.2 |
Fixed Version(s) | 9.22, 10.10, 11.3, 12.0 Alpha |
CVSS Score 4.0 | 2.3 |
Reported By |
Affected Version(s) | 9.21, 10.9, 11.2 |
Fixed Version(s) | 9.22, 10.10, 11.3, 12.0 Alpha |
CVSS Score 4.0 | 8.7 |
Reported By | André Schweigert (FAU|ILIAS) |
Affected Version(s) | 9.21, 10.9, 11.2 |
Fixed Version(s) | 9.22, 10.10, 11.3, 12.0 Alpha |
CVSS Score 4.0 | 8.7 |
Reported By | Ilja Lukin (Fachhochschule Dortmund) |
Affected Version(s) | 9.21, 10.9, 11.2 |
Fixed Version(s) | 9.22, 10.10, 11.3, 12.0 Alpha |
CVSS Score 4.0 | 8.8 |
Reported By | André Schweigert ( FAU | ILIAS ) |
Affected Version(s) | 10.9, 11.2 |
Fixed Version(s) | 10.10, 11.3, 12.0 Alpha |
CVSS Score 4.0 | 2.1 |
Reported By | Ingmar Szmais (Databay AG) |
Affected Version(s) | 9.21, 10.9, 11.2 |
Fixed Version(s) | 9.22, 10.10, 11.3, 12.0 Alpha |
CVSS Score 4.0 | 8.7 |
CVE-ID | CVE-2026-18745 |
Reported By | André Schweigert ( FAU | ILIAS ) |
Affected Version(s) | 9.21, 10.9, 11.2 |
Fixed Version(s) | 9.22, 10.10, 11.3, 12.0 Alpha |
CVSS Score 4.0 | 9.2 |
Reported By | André Schweigert ( FAU | ILIAS ) |
Affected Version(s) | 9.21, 10.9, 11.2 |
Fixed Version(s) | 9.22, 10.10, 11.3, 12.0 Alpha |
CVSS Score 4.0 | 7.1 |
Reported By | André Schweigert ( FAU | ILIAS ) |
Affected Version(s) | 9.21, 10.9, 11.2 |
Fixed Version(s) | 9.22, 10.10, 11.3, 12.0 Alpha |
CVSS Score 4.0 | 6.9 |
Reported By | Ilja Lukin (Fachhochschule Dortmund) |
Affected Version(s) | 9.21, 10.9, 11.2 |
Fixed Version(s) | 9.22, 10.10, 11.3, 12.0 Alpha |
CVSS Score 4.0 | - |
Reported By | Franziska Senze |