VulnerabilityModified
CVE-2025-11346
A vulnerability has been found in ILIAS up to 8.23/9.13/10.1.
MEDIUM 5.3EPSS 0.44%
Does this matter?
Lower severity and a low EPSS score (0.44%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability has been found in ILIAS up to 8.23/9.13/10.1. This affects the function unserialize of the component Base64 Decoding Handler. Such manipulation of the argument f_settings leads to deserialization. It is possible to launch the attack remotely. Upgrading to version 8.24, 9.14 and 10.2 is able to mitigate this issue. It is advisable to upgrade the affected component.
- CVSS 4.0
- 5.3 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.44% probability · 37th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20, CWE-502
- Affected
- ilias/ilias
- Source
- cna@vuldb.com
References
- https://vuldb.com/?ctiid.327231Permissions Required, VDB Entry
- https://vuldb.com/?id.327231Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.664892Third Party Advisory, VDB Entry
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2113Third Party Advisory
- https://srlabs.de/blog/breaking-ilias-part-2-three-to-rce
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.