Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2rvg-p9mc-wr6c

Опубликовано: 28 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 4

Описание

ILIAS Learning Management System 4.3 contains a server-side request forgery vulnerability that allows attackers to read local files through portfolio PDF export functionality. Attackers can inject a script that uses XMLHttpRequest to retrieve local file contents when the portfolio is exported to PDF.

ILIAS Learning Management System 4.3 contains a server-side request forgery vulnerability that allows attackers to read local files through portfolio PDF export functionality. Attackers can inject a script that uses XMLHttpRequest to retrieve local file contents when the portfolio is exported to PDF.

EPSS

Процентиль: 9%
0.00031
Низкий

6.9 Medium

CVSS4

4 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 4
nvd
10 дней назад

ILIAS Learning Management System 4.3 contains a server-side request forgery vulnerability that allows attackers to read local files through portfolio PDF export functionality. Attackers can inject a script that uses XMLHttpRequest to retrieve local file contents when the portfolio is exported to PDF.

EPSS

Процентиль: 9%
0.00031
Низкий

6.9 Medium

CVSS4

4 Medium

CVSS3

Дефекты

CWE-918