Junglewise Threat Intelligence

CVE-2023-32778: ILIAS arbitrary code execution via ZIP upload

CVE-2023-32778 · Severity: low · CVSS 3.3 · Published 2026-09-14

Technologies: ILIAS.

Executive brief

ILIAS is an open-source learning management system used by educational institutions to deliver online courses and manage student learning. An attacker can upload malicious ZIP files to execute arbitrary code on the server, potentially gaining full control of the platform and access to student data, course materials, and institutional information.

Technical details

The vulnerability exists in ILIAS's ZIP upload handling mechanism, allowing arbitrary code execution through maliciously crafted ZIP archives. The issue affects multiple versions: 6.23, 7 before 7.22, and 8.1. Attack vectors depend on the specific upload functionality exposed; typical preconditions may include authenticated access or public upload endpoints. An attacker exploiting this can achieve remote code execution on the server. Patches are available in ILIAS 7.22 and later versions.

Affected products

  • ILIAS ILIAS 6.23, 7 before 7.22, 8.1

Timeline

  • 2026-09-14: disclosed

References