<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>ILIAS (&lt; 9.24, 10.x &lt; 10.12, 11.x &lt; 11.5) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/ilias--9.24-10.x--10.12-11.x--11.5/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 08 Oct 2026 17:11:47 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/ilias--9.24-10.x--10.12-11.x--11.5/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Argument Injection in ILIAS assImagemapQuestionGUI</title><link>https://feed.craftedsignal.io/briefs/2026-10-ilias-arg-injection/</link><pubDate>Thu, 08 Oct 2026 17:11:47 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-ilias-arg-injection/</guid><description>An argument injection vulnerability in the ILIAS assImagemapQuestionGUI component allows authenticated question authors to achieve remote code execution by injecting ImageMagick options via crafted filenames.</description><content:encoded><![CDATA[<p>ILIAS, an open-source learning management system, contains an argument injection vulnerability identified as CVE-2026-107639, affecting versions before 9.24, 10.x before 10.12, and 11.x before 11.5. The vulnerability resides within the <code>assImagemapQuestionGUI</code> component, which handles image uploads for question-based assessments. Attackers with permission to author questions can upload image files with specially crafted, tab-separated filenames. Because the application's implementation of <code>escapeshellcmd()</code> fails to neutralize these injected arguments, the underlying ImageMagick <code>convert</code> utility treats the filename segments as functional command-line options. By manipulating these options, an attacker can force the utility to write arbitrary content to a file, such as a PHP shell, within the web-accessible directory. Successful exploitation results in full remote code execution under the privileges of the web server process.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>The attacker authenticates to the ILIAS platform with question authoring privileges.</li>
<li>The attacker creates a new ImageMap question or modifies an existing one.</li>
<li>The attacker prepares a malicious image file where the filename contains tab-separated ImageMagick arguments.</li>
<li>The attacker uploads the crafted file to the <code>assImagemapQuestionGUI</code> interface.</li>
<li>The application passes the malicious filename directly to the ImageMagick <code>convert</code> utility on the host OS.</li>
<li>The <code>convert</code> utility interprets the injected arguments, triggering a file write operation to a location under the web root.</li>
<li>The attacker browses to the newly created, malicious PHP file via the web browser.</li>
<li>The server executes the embedded PHP code, providing the attacker with remote code execution.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows an authenticated attacker to execute arbitrary code on the host server. This impact is critical for institutional deployments of ILIAS, as compromised instances may grant attackers access to sensitive student data, grades, and potentially administrative credentials for connected authentication systems. All versions of ILIAS below 9.24, 10.12, and 11.5 are considered vulnerable.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade all ILIAS instances to version 9.24, 10.12, 11.5, or later immediately to patch CVE-2026-107639.</li>
<li>Audit web server access logs for anomalous requests targeting newly created files or files with unexpected extensions within the ILIAS upload directories.</li>
<li>Restrict question authoring privileges to trusted users until the software has been updated.</li>
<li>Ensure that the ImageMagick <code>convert</code> utility is restricted from performing file-write operations outside of designated temporary directories using security policy configurations.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>rce</category><category>vulnerability</category></item></channel></rss>