CVE-2026-108113High· 8.8▾ TwilightILIAS before 9.24, 10.12, and 11.5 contains an unrestricted file upload vulnerability in QTI question import image handling (ilQtiMatImageSecurity) that allows authenticated authors to write executable files. Attackers with question pool…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
ILIAS before 9.24, 10.12, and 11.5 contains an unrestricted file upload vulnerability in QTI question import image handling (ilQtiMatImageSecurity) that allows authenticated authors to write executable files. Attackers with question pool import rights can import a crafted archive writing a .htaccess and PHP file to the web-served image directory, achieving remote code execution as the web server user.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-11347High· 7.3A vulnerability was found in code-projects Student Crud Operation up to 3.3
CVE-2025-11318High· 7.3A security flaw has been discovered in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0
CVE-2025-11908Medium· 6.3A security flaw has been discovered in Shenzhen Ruiming Technology Streamax Crocus 1.3.40
CVE-2025-11398Medium· 6.3A weakness has been identified in SourceCodester Hotel and Lodge Management System 1.0
CVE-2025-11354Medium· 6.3A flaw has been found in code-projects Online Hotel Reservation System 1.0
CVE-2025-11508Medium· 4.7A security vulnerability has been detected in code-projects Voting System 1.0