ZeroHour

CVE-2022-31266

CVSS 3.1
4.3 medium
EPSS
<1%p56
Published
()
Modified
Description

In ILIAS through 7.10, lack of verification when changing an email address (on the Profile Page) allows remote attackers to take over accounts.

Vendors
ilias
Products
ilias
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.