CVE-2025-11344

Source
https://cve.org/CVERecord?id=CVE-2025-11344
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-11344.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-11344
Published
2025-10-06T19:15:34.523Z
Modified
2026-04-10T05:20:39.149518Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A vulnerability was detected in ILIAS up to 8.23/9.13/10.1. Affected by this vulnerability is an unknown functionality of the component Certificate Import Handler. The manipulation results in Remote Code Execution. The attack may be performed from remote. Upgrading to version 8.24, 9.14 and 10.2 addresses this issue. It is recommended to upgrade the affected component.

References

Affected packages

Git / github.com/ilias-elearning/ilias

Affected ranges

Type
GIT
Repo
https://github.com/ilias-elearning/ilias
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "8.23"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "9.13"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "10.1"
        }
    ]
}

Affected versions

v10.*
v10.0
v10.0_beta1
v10.0_beta2
v10.0_beta3
v10.1
v5.*
v5.1.0beta2
v5.3.0beta1
v8.*
v8.0_beta1
v8.0_beta2
v8.0_beta4
v8.1
v8.10
v8.11
v8.12
v8.13
v8.14
v8.15
v8.16
v8.17
v8.18
v8.19
v8.2
v8.20
v8.21
v8.22
v8.23
v8.3
v8.4
v8.5
v8.6
v8.7
v8.8
v8.9
v9.*
v9.0
v9.0_beta1
v9.0_beta3
v9.1
v9.10
v9.12
v9.13
v9.3
v9.4
v9.5
v9.6
v9.7
v9.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-11344.json"