CVE-2025-11345

MEDIUM

ILIAS <8.23/9.13/10.1 - Deserialization

Title source: llm

Description

A flaw has been found in ILIAS up to 8.23/9.13/10.1. Affected by this issue is the function unserialize of the component Test Import. This manipulation causes deserialization. It is possible to initiate the attack remotely. Upgrading to version 8.24, 9.14 and 10.2 can resolve this issue. Upgrading the affected component is advised.

Scores

CVSS v3 5.5
EPSS 0.0011
EPSS Percentile 29.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

Classification

CWE
CWE-502 CWE-20
Status published

Affected Products (3)

ilias/ilias
ilias/ilias
ilias/ilias

Timeline

Published Oct 06, 2025
Tracked Since Feb 18, 2026