CNNVD-202601-4731 Information

CNNVD ID

CNNVD-202601-4731

CVE-2020-36944

  • CNNVD Published: 2026-01-28

Description (Chinese)

ILIAS是ILIAS开源的一套开源的学习管理系统。 ILIAS 4.3版本存在代码问题漏洞,该漏洞源于portfolio PDF导出功能存在服务器端请求伪造,可能导致读取本地文件。

Description (English)

ILIAS is an open-source learning management system for ILIAS open sources. There is a code gap in ILIAS 4.3, which stems from the existence of a server request for forgery from the portfolio PDF export function, which may lead to reading local files.

Hazard Level

High

Vulnerability Type

代码问题

Affected Vendor

ILIAS

Published

2026-01-28

Last Modified

2026-02-24

References

https://github.com/ILIAS-eLearning/ILIAS https://www.exploit-db.com/exploits/49148 https://www.ilias.de/ https://www.vulncheck.com/advisories/ilias-learning-management-system-ssrf

Patch

https://www.ilias.de/

Share on: