Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 09 Oct 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ILIAS before 9.24, 10.12, and 11.5 contains an unrestricted file upload vulnerability in QTI question import image handling (ilQtiMatImageSecurity) that allows authenticated authors to write executable files. Attackers with question pool import rights can import a crafted archive writing a .htaccess and PHP file to the web-served image directory, achieving remote code execution as the web server user. | |
| Title | ILIAS before 9.24, 10.12, and 11.5 Unrestricted File Upload via QTI Import | |
| First Time appeared |
Ilias
Ilias ilias |
|
| Weaknesses | CWE-434 | |
| CPEs | cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ilias
Ilias ilias |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-09T15:04:59.582Z
Reserved: 2026-10-09T13:44:40.884Z
Link: CVE-2026-108113
No data.
Status : Deferred
Published: 2026-10-09T16:17:26.917
Modified: 2026-10-09T16:17:27.067
Link: CVE-2026-108113
No data.
OpenCVE Enrichment
Updated: 2026-10-09T17:45:10Z