CVE-2020-36944: Ilias

Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.

ILIAS Learning Management System 4.3 contains a server-side request forgery vulnerability that allows attackers to read local files through portfolio PDF export functionality. Attackers can inject a script that uses XMLHttpRequest to retrieve local file contents when the portfolio is exported to PDF.

Affected products

  • Ilias Ilias: from 4.3.0, up to and including 5.1.0

Published 2026-01-28. Last modified 2026-06-17.