Update

Due to a short software update, docu.ilias.de will be unavailable from 14:45 CEST for approximately 10 minutes.

25. Internationale ILIAS-Konferenz

Security-Blog

Die Security-Gruppe informiert über behobene Sicherheitslücken in ILIAS

July 2026

Tokar, David [tokard], Wolf, Fabian [fwolf] - 7. Jul 2026, 17:00

Following 5 security issues have been resolved:

0047800: Stored XSS via HTML attribute injection
0047834: Add RBAC check for Repository Objects
0047887: SOAP: Insecure Direct Object Reference (IDOR)
0047952: Object: Remove Information on Temp File Location from Error Message
0047954: Notes: Insufficient access checks

· Link

Tokar, David [tokard], Wolf, Fabian [fwolf] - 7. Jul 2026, 16:30

Following 5 security issues have been resolved:

0047800: Stored XSS via HTML attribute injection
0047834: Add RBAC check for Repository Objects
0047887: SOAP: Insecure Direct Object Reference (IDOR)
0047952: Object: Remove Information on Temp File Location from Error Message
0047954: Notes: Insufficient access checks

· Link

Tokar, David [tokard], Wolf, Fabian [fwolf] - 7. Jul 2026, 16:00

Following 6 security issues have been resolved:

0046642: Data Collection: Stored XSS with TinyMCE
0047800: Stored XSS via HTML attribute injection
0047834: Add RBAC check for Repository Objects
0047887: SOAP: Insecure Direct Object Reference (IDOR)
0047952: Object: Remove Information on Temp File Location from Error Message
0047954: Notes: Insufficient access checks

· Link

May 2026

Tokar, David [tokard], Wolf, Fabian [fwolf] - 26. May 2026, 17:30

Following 9 security issues have been resolved:

0047258: SOAP: Unauthorized function call
0047472: SQL injection in SOAP
0047581: Broken Access Control in SOAP
0047691: SQL injection in ILIAS MyStaff
0047692: Fixes a path traversal vulnerability in the custom icon upload
0047749: Fix Sanitation of Answer Options in the Presentation of Statistics in the View to Correct Points.
0047770: Tracking: validate sort field from LP participants table
0047778: Authenticated SQLi in SCORM2004
0047787: Add an AccessControl-Check to TileImageUploadHandler

· Link

Tokar, David [tokard], Wolf, Fabian [fwolf] - 26. May 2026, 17:00

Following 9 security issues have been resolved:

0047258: SOAP: Unauthorized function call
0047472: SQL injection in SOAP
0047581: Broken Access Control in SOAP
0047691: SQL injection in ILIAS MyStaff
0047692: Fixes a path traversal vulnerability in the custom icon upload
0047749: Fix Sanitation of Answer Options in the Presentation of Statistics in the View to Correct Points.
0047770: Tracking: validate sort field from LP participants table
0047778: Authenticated SQLi in SCORM2004
0047787: Add an AccessControl-Check to TileImageUploadHandler

· Link