CVE-2023-32778
Received Received - Intake

Arbitrary Code Execution via ZIP Upload in ILIAS

Vulnerability report for CVE-2023-32778, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: MITRE

Description

An issue was discovered in ILIAS 6.23, 7 before 7.22, and 8.1. An attacker can execute arbitrary code via ZIP upload.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
ilias ilias to 7.22 (exc)
ilias ilias 8.1
ilias ilias 6.23

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-23 The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2023-32778 is a vulnerability in ILIAS versions 6.23, 7 before 7.22, and 8.1. It allows an attacker to execute arbitrary code by uploading a malicious ZIP file. The issue stems from improper handling of uploaded files, enabling code execution without proper validation.

Detection Guidance

Detection requires checking ILIAS versions and monitoring for unauthorized ZIP uploads. Verify installed versions against patched releases (7.22+ or 8.1+). Inspect system logs for unexpected ZIP file uploads or unusual file execution patterns in ILIAS directories.

Impact Analysis

This vulnerability could allow attackers to run arbitrary code on your ILIAS server. If exploited, it may lead to unauthorized access, data breaches, or system compromise. Users should update to patched versions to prevent potential attacks.

Compliance Impact

This vulnerability could potentially lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR and HIPAA. Unauthorized access to restricted areas of the system could expose personal or health-related information, triggering non-compliance with data protection regulations.

Mitigation Strategies

Update ILIAS to the latest patched version (7.22 or 8.1) to address the improper access control flaw. Ensure authentication and authorization checks are properly enforced in the system.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2023-32778. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart