---
id: CVE-2026-108113
title: >-
  ILIAS before 9.24, 10.12, and 11.5 contains an unrestricted file upload
  vulnerability in QTI question import image handling (ilQtiMatImageSecurity)
  that allows authenticated authors to write executable files
summary: >-
  ILIAS before 9.24, 10.12, and 11.5 contains an unrestricted file upload
  vulnerability in QTI question import image handling (ilQtiMatImageSecurity)
  that allows authenticated authors to write executable files. Attackers with
  question pool…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-434
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T16:17:27.067'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-108113'
references:
  - url: 'https://docu.ilias.de/go/blog/15821/950'
    label: disclosure@vulncheck.com
  - url: 'https://docu.ilias.de/go/blog/15821/951'
    label: disclosure@vulncheck.com
  - url: 'https://docu.ilias.de/go/blog/15821/952'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/ILIAS-eLearning/ILIAS'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/ILIAS-eLearning/ILIAS/blob/v10.11/components/ILIAS/QTI/classes/class.ilQtiMatImageSecurity.php#L110-L122
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/ILIAS-eLearning/ILIAS/commit/47c8462bf46bbebd543a9f3b39c7896b0e9e7362
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/ILIAS-eLearning/ILIAS/commit/58ee5b1767212530f9948adb0e7d5aecec66ce60
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/ILIAS-eLearning/ILIAS/commit/5b200351330bee698432a45c0877c5bc694c367a
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/ilias-before-9.24-10.12-and-11.5-unrestricted-file-upload-via-qti-import
    label: disclosure@vulncheck.com
tags:
  - nvd
ingestedAt: '2026-10-09T17:04:42.811Z'
---

## Overview

ILIAS before 9.24, 10.12, and 11.5 contains an unrestricted file upload vulnerability in QTI question import image handling (ilQtiMatImageSecurity) that allows authenticated authors to write executable files. Attackers with question pool import rights can import a crafted archive writing a .htaccess and PHP file to the web-served image directory, achieving remote code execution as the web server user.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
