CVE-2023-32778 PUBLISHED

Assigner: mitre
Reserved: 15.05.2023 Published: 14.09.2026 Updated: 14.09.2026

An issue was discovered in ILIAS 6.23, 7 before 7.22, and 8.1. An attacker can execute arbitrary code via ZIP upload.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N
CVSS Score: 3.3

Product Status

Vendor ILIAS
Product ILIAS
Versions Default: unknown
  • Version 6.23 is affected
  • affected from 7 to 7.22 (excl.)
  • Version 8.1 is affected

References

Problem Types

  • CWE-23 Relative Path Traversal CWE