CVE-2024-33529

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
21/05/2024
Last modified:
04/06/2025

Description

ILIAS 7 before 7.30 and ILIAS 8 before 8.11 as well as ILIAS 9.0 allow remote authenticated attackers with administrative privileges to execute operating system commands via file uploads with dangerous types.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:* 7.0 (including) 7.30 (excluding)
cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:* 8.0 (including) 8.11 (excluding)
cpe:2.3:a:ilias:ilias:9.0:*:*:*:*:*:*:*