Breaking

Security Advisory: Achieving PHP Code Execution in ILIAS eLearning LMS before v7.30/v8.11/v9.1

During my Bachelor’s thesis, I identified several XSS vulnerabilities and a PHP Code Execution vulnerability via an insecure file upload in the learning management system (LMS) ILIAS. The XSS vulnerability can be chained with the code execution vulnerability so that attackers with tutor privileges in at least one course can perform this exploit chain.

The Bachelor’s thesis was motivated by the ever-increasing number of compromised universities in Germany1^(,)2^(,)3^(,)4^(,)5. The thesis analyzed the importance of LMS systems in that context, as those services are often exposed to the internet.

Continue reading