Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-36944

Опубликовано: 28 янв. 2026
Источник: nvd
CVSS3: 4
EPSS Низкий

Описание

ILIAS Learning Management System 4.3 contains a server-side request forgery vulnerability that allows attackers to read local files through portfolio PDF export functionality. Attackers can inject a script that uses XMLHttpRequest to retrieve local file contents when the portfolio is exported to PDF.

EPSS

Процентиль: 9%
0.00031
Низкий

4 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 4
github
10 дней назад

ILIAS Learning Management System 4.3 contains a server-side request forgery vulnerability that allows attackers to read local files through portfolio PDF export functionality. Attackers can inject a script that uses XMLHttpRequest to retrieve local file contents when the portfolio is exported to PDF.

EPSS

Процентиль: 9%
0.00031
Низкий

4 Medium

CVSS3

Дефекты

CWE-918