← back
CVE-2020-36944

ILIAS Learning Management System 4.3 - SSRF

CVSS 6.9 MEDIUMEPSS 0.2%CWE-918
ILIAS Learning Management System 4.3 contains a server-side request forgery vulnerability that allows attackers to read local files through portfolio PDF export functionality. Attackers can inject a script that uses XMLHttpRequest to retrieve local file contents when the portfolio is exported to PDF.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →