CVE-2026-108113 PUBLISHED

ILIAS before 9.24, 10.12, and 11.5 Unrestricted File Upload via QTI Import

Assigner: VulnCheck
Reserved: 09.10.2026 Published: 09.10.2026 Updated: 09.10.2026

ILIAS before 9.24, 10.12, and 11.5 contains an unrestricted file upload vulnerability in QTI question import image handling (ilQtiMatImageSecurity) that allows authenticated authors to write executable files. Attackers with question pool import rights can import a crafted archive writing a .htaccess and PHP file to the web-served image directory, achieving remote code execution as the web server user.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor ILIAS-eLearning e.V.
Product ILIAS
Versions Default: unaffected
  • affected from 5.2.8 to 9.24 (excl.)
  • affected from 10.0 to 10.12 (excl.)
  • affected from 11.0 to 11.5 (excl.)

Credits

  • André Schweigert (SchweigertIT) finder

References

Problem Types

  • Unrestricted Upload of File with Dangerous Type CWE