CVE-2023-36487: Ilias

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

The password reset function in ILIAS 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows remote attackers to take over the account.

Affected products

  • Ilias Ilias: from 7.0, up to and including 7.20; from 8.0, up to and including 8.1

Published 2023-06-29. Last modified 2026-06-17.