CVE-2026-107639

Source
https://cve.org/CVERecord?id=CVE-2026-107639
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107639.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-107639
Published
2026-10-08T14:10:35Z
Modified
2026-10-10T02:47:24Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
ILIAS before 9.24, 10.12, and 11.5 Argument Injection via Image Map Question Upload Filename
Details

ILIAS before 9.24, 10.x before 10.12 and 11.x before 11.5 contains an argument injection vulnerability in assImagemapQuestionGUI that allows question authors to inject ImageMagick convert options via uploaded image filenames. Attackers can embed tab-separated options, which escapeshellcmd() does not neutralise, to write a PHP file under the web root and achieve remote code execution.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-88"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107639.json"
}
References

Affected packages

Git / github.com/ilias-elearning/ilias

Affected ranges

Type
GIT
Repo
https://github.com/ilias-elearning/ilias
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "9.0"
        },
        {
            "fixed": "9.24"
        },
        {
            "introduced": "10.0"
        },
        {
            "fixed": "10.12"
        },
        {
            "introduced": "11.0"
        },
        {
            "fixed": "11.5"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v10.*
v10.0
v10.10
v10.11
v10.2
v10.3
v10.4
v10.5
v10.6
v10.7
v10.8
v10.9
v11.*
v11.0
v11.1
v11.2
v11.3
v11.4
v3.*
v3.8
v9.*
v9.0
v9.1
v9.10
v9.12
v9.13
v9.15
v9.16
v9.17
v9.18
v9.19
v9.20
v9.21
v9.22
v9.23
v9.3
v9.4
v9.5
v9.6
v9.7
v9.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107639.json"