{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/ilias--9.24-10.x--10.12-11.x--11.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-107639"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ILIAS (\u003c 9.24, 10.x \u003c 10.12, 11.x \u003c 11.5)"],"_cs_severities":["high"],"_cs_tags":["web-application","rce","vulnerability"],"_cs_type":"advisory","_cs_vendors":["ILIAS"],"content_html":"\u003cp\u003eILIAS, an open-source learning management system, contains an argument injection vulnerability identified as CVE-2026-107639, affecting versions before 9.24, 10.x before 10.12, and 11.x before 11.5. The vulnerability resides within the \u003ccode\u003eassImagemapQuestionGUI\u003c/code\u003e component, which handles image uploads for question-based assessments. Attackers with permission to author questions can upload image files with specially crafted, tab-separated filenames. Because the application's implementation of \u003ccode\u003eescapeshellcmd()\u003c/code\u003e fails to neutralize these injected arguments, the underlying ImageMagick \u003ccode\u003econvert\u003c/code\u003e utility treats the filename segments as functional command-line options. By manipulating these options, an attacker can force the utility to write arbitrary content to a file, such as a PHP shell, within the web-accessible directory. Successful exploitation results in full remote code execution under the privileges of the web server process.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker authenticates to the ILIAS platform with question authoring privileges.\u003c/li\u003e\n\u003cli\u003eThe attacker creates a new ImageMap question or modifies an existing one.\u003c/li\u003e\n\u003cli\u003eThe attacker prepares a malicious image file where the filename contains tab-separated ImageMagick arguments.\u003c/li\u003e\n\u003cli\u003eThe attacker uploads the crafted file to the \u003ccode\u003eassImagemapQuestionGUI\u003c/code\u003e interface.\u003c/li\u003e\n\u003cli\u003eThe application passes the malicious filename directly to the ImageMagick \u003ccode\u003econvert\u003c/code\u003e utility on the host OS.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003econvert\u003c/code\u003e utility interprets the injected arguments, triggering a file write operation to a location under the web root.\u003c/li\u003e\n\u003cli\u003eThe attacker browses to the newly created, malicious PHP file via the web browser.\u003c/li\u003e\n\u003cli\u003eThe server executes the embedded PHP code, providing the attacker with remote code execution.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows an authenticated attacker to execute arbitrary code on the host server. This impact is critical for institutional deployments of ILIAS, as compromised instances may grant attackers access to sensitive student data, grades, and potentially administrative credentials for connected authentication systems. All versions of ILIAS below 9.24, 10.12, and 11.5 are considered vulnerable.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all ILIAS instances to version 9.24, 10.12, 11.5, or later immediately to patch CVE-2026-107639.\u003c/li\u003e\n\u003cli\u003eAudit web server access logs for anomalous requests targeting newly created files or files with unexpected extensions within the ILIAS upload directories.\u003c/li\u003e\n\u003cli\u003eRestrict question authoring privileges to trusted users until the software has been updated.\u003c/li\u003e\n\u003cli\u003eEnsure that the ImageMagick \u003ccode\u003econvert\u003c/code\u003e utility is restricted from performing file-write operations outside of designated temporary directories using security policy configurations.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-08T17:11:47Z","date_published":"2026-10-08T17:11:47Z","id":"https://feed.craftedsignal.io/briefs/2026-10-ilias-arg-injection/","summary":"An argument injection vulnerability in the ILIAS assImagemapQuestionGUI component allows authenticated question authors to achieve remote code execution by injecting ImageMagick options via crafted filenames.","title":"Argument Injection in ILIAS assImagemapQuestionGUI","url":"https://feed.craftedsignal.io/briefs/2026-10-ilias-arg-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - ILIAS (\u003c 9.24, 10.x \u003c 10.12, 11.x \u003c 11.5)","version":"https://jsonfeed.org/version/1.1"}