CVE-2025-11345
MEDIUMILIAS <8.23/9.13/10.1 - Deserialization
Title source: llmDescription
A flaw has been found in ILIAS up to 8.23/9.13/10.1. Affected by this issue is the function unserialize of the component Test Import. This manipulation causes deserialization. It is possible to initiate the attack remotely. Upgrading to version 8.24, 9.14 and 10.2 can resolve this issue. Upgrading the affected component is advised.
References (5)
Scores
CVSS v3
5.5
EPSS
0.0011
EPSS Percentile
29.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Classification
CWE
CWE-502
CWE-20
Status
published
Affected Products (3)
ilias/ilias
ilias/ilias
ilias/ilias
Timeline
Published
Oct 06, 2025
Tracked Since
Feb 18, 2026