Multiple critical vulnerabilities in the ILIAS open-source e-Learning platform, including security bypass, information disclosure, and Cross-Site Scripting, can be exploited remotely by an attacker. The CVSS Base Score is 9.1. Affected versions are ILIAS prior to 11.2, prior to 10.9, and prior to 9.21.
[WID-SEC-2026-2230] ILIAS: Mehrere Schwachstellen CVSS Base Score 9.1 (kritisch) CVSS Temporal Score 7.9 (hoch) Remoteangriff ja Datum 07.07.2026 Stand 08.07.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux Sonstiges UNIX Windows Produktbeschreibung ILIAS ist eine Open Source e-Learning Lösung. Produkte 07.07.2026 Open Source ILIAS <11.2 Open Source ILIAS <10.9 Open Source ILIAS <9.21 Angriff Angriff Ein Angreifer kann mehrere Schwachstellen in ILIAS ausnutzen, um Sicherheitsvorkehrungen zu umgehen, sensible Informationen offenzulegen oder Cross-Site-Scripting-Angriffe durchzuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben