ILIAS before 9.24, 10.12, and 11.5 contains an unrestricted file upload vulnerability in QTI question import image handling (ilQtiMatImageSecurity) that allows authenticated authors to write executable files. Attackers with question pool import rights can import a crafted archive writing a .htaccess and PHP file to the web-served image directory, achieving remote code execution as the web server user.
https://github.com/ILIAS-eLearning/ILIAS/commit/5b200351330bee698432a45c0877c5bc694c367a
https://github.com/ILIAS-eLearning/ILIAS/commit/58ee5b1767212530f9948adb0e7d5aecec66ce60
https://github.com/ILIAS-eLearning/ILIAS/commit/47c8462bf46bbebd543a9f3b39c7896b0e9e7362
Published: 2026-10-09
Updated: 2026-10-09
Base Score: 9
Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C
Severity: High
Base Score: 8.8
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity: High
Base Score: 8.7
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Severity: High