CVE Vulnerabilities

CVE-2023-36487

Published: Jun 29, 2023 | Modified: Jul 06, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The password reset function in ILIAS 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows remote attackers to take over the account.

Affected Software

Name Vendor Start Version End Version
Ilias Ilias 7.0 (including) 7.20 (including)
Ilias Ilias 8.0 (including) 8.1 (including)

References