In ILIAS through 7.10, lack of verification when changing an email address (on the Profile Page) allows remote attackers to take over accounts.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://www.bcksec.com/services/ | not applicable |
https://medium.com/%40bcksec/in-ilias-through-7-10-620c0de685ee | third party advisory |