CVE-2025-11344Disclosure(ilias / ilias)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in ILIAS up to 8.23/9.13/10.1. Affected by this vulnerability is an unknown functionality of the component Certificate Import Handler. The manipulation results in Remote Code Execution. The attack may be performed from remote. Upgrading to version 8.24, 9.14 and 10.2 addresses this issue. It is recommended to upgrade the affected component.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ilias

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
ilias

3 versions affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-12: 102-12
Signal classification1 categories
Disclosure
1100.0%
Referenced assets2 URLs
Full discourse1 post
  • Mr. OS@ksg93rd
    Disclosure

    #exploit #AppSec Breaking ILIAS Part 1 - From Open Redirect to Admin https://srlabs.de/blog/breaking-ilias-part-1-from-open-redirect-to-admin Part 2 - Three to RCE https://srlabs.de/blog/breaking-ilias-part-2-three-to-rce // three previously unknown vulnerabilities (CVE-2024-48273, CVE-2025-11344, CVE-2025-11345) enabling RCE in versions 8, 9, 10 of the widely used learning management system ILIAS

    Post summary

    Three newly discovered CVEs in ILIAS allow remote code execution; blog posts discuss the vulnerabilities but no PoC, exploit tool, active exploitation, or patch details are provided.

    00000238
    3.1K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appiliasilias10.1--
Appiliasilias8.23--
Appiliasilias9.13--

Explore more