CVE-2020-36944: Ilias
Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.
ILIAS Learning Management System 4.3 contains a server-side request forgery vulnerability that allows attackers to read local files through portfolio PDF export functionality. Attackers can inject a script that uses XMLHttpRequest to retrieve local file contents when the portfolio is exported to PDF.
Affected products
- Ilias Ilias: from 4.3.0, up to and including 5.1.0
Published 2026-01-28. Last modified 2026-06-17.