
#exploit #AppSec Breaking ILIAS Part 1 - From Open Redirect to Admin https://srlabs.de/blog/breaking-ilias-part-1-from-open-redirect-to-admin Part 2 - Three to RCE https://srlabs.de/blog/breaking-ilias-part-2-three-to-rce // three previously unknown vulnerabilities (CVE-2024-48273, CVE-2025-11344, CVE-2025-11345) enabling RCE in versions 8, 9, 10 of the widely used learning management system ILIAS
Post summary
Three newly discovered CVEs in ILIAS allow remote code execution; blog posts discuss the vulnerabilities but no PoC, exploit tool, active exploitation, or patch details are provided.
