VulnerabilityAnalyzed
CVE-2022-31266
In ILIAS through 7.10, lack of verification when changing an email address (on the Profile Page) allows remote attackers to take over accounts.
MEDIUM 4.3EPSS 0.84%
Does this matter?
Lower severity and a low EPSS score (0.84%). Track it; it rarely justifies an emergency change on its own.
Description
In ILIAS through 7.10, lack of verification when changing an email address (on the Profile Page) allows remote attackers to take over accounts.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.84% probability · 56th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- ilias/ilias
- Source
- cve@mitre.org
References
- https://medium.com/%40bcksec/in-ilias-through-7-10-620c0de685eeThird Party Advisory
- https://www.bcksec.com/services/Not Applicable
- https://medium.com/%40bcksec/in-ilias-through-7-10-620c0de685eeThird Party Advisory
- https://www.bcksec.com/services/Not Applicable
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.