VulnerabilityModified
CVE-2020-23995
An information disclosure vulnerability in ILIAS before 5.3.19, 5.4.12 and 6.0 allows remote authenticated attackers to get the upload data path via a workspace upload.
MEDIUM 6.5EPSS 1.55%
Does this matter?
Lower severity and a low EPSS score (1.55%). Track it; it rarely justifies an emergency change on its own.
Description
An information disclosure vulnerability in ILIAS before 5.3.19, 5.4.12 and 6.0 allows remote authenticated attackers to get the upload data path via a workspace upload.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.55% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-209
- Affected
- ilias/ilias
- Source
- cve@mitre.org
References
- https://cwe.mitre.org/data/definitions/209.htmlTechnical Description
- https://docu.ilias.de/goto_docu_pg_118817_35.htmlRelease Notes, Vendor Advisory
- https://docu.ilias.de/goto_docu_pg_122177_35.htmlRelease Notes, Vendor Advisory
- https://docu.ilias.de/goto_docu_pg_124761_35.htmlRelease Notes, Vendor Advisory
- https://github.com/ILIAS-eLearning/ILIAS/commit/94d9b16010ec3abeae8d2cbb05622ccd999119adPatch, Third Party Advisory
- https://cwe.mitre.org/data/definitions/209.htmlTechnical Description
- https://docu.ilias.de/goto_docu_pg_118817_35.htmlRelease Notes, Vendor Advisory
- https://docu.ilias.de/goto_docu_pg_122177_35.htmlRelease Notes, Vendor Advisory
- https://docu.ilias.de/goto_docu_pg_124761_35.htmlRelease Notes, Vendor Advisory
- https://github.com/ILIAS-eLearning/ILIAS/commit/94d9b16010ec3abeae8d2cbb05622ccd999119adPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.