<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
	<channel>
		<title>Security-Blog</title>
		<link>https://docu10.ilias.de/go/blog/15821</link>
		<description>Die Security-Gruppe informiert über behobene Sicherheitslücken in ILIAS</description>
		
		
		

		
		<item>
			<title>ILIAS 10.4</title>
			<link>https://docu10.ilias.de/go/blog/15821/894</link>
			<description><![CDATA[<p class="ilc_Paragraph ilc_text_block_Standard">Following 8 security issues have been resolved:<br/><br/>0046023: SOAP: Unauthorized function calls<br/>0046024: SOAP: Unauthorized data exposure<br/>0046025: SOAP: Missing source permission check<br/>0046496: ilServer: Apache Tika multiple XXE vulnerabilities<br/>0045883: BackgroundTasks: Missind CSRF token for two commands in ilBTControllerGUI<br/>0045884: BackgroundTasks: Open redirect in ilBTControllerGUI<br/>0045900: BackgroundTasks: Unauthorized deletion of tasks<br/>0045905: Repository: Stored XSS via SVG file upload of custom icons</p><div style="clear:both;"></div>]]></description>
			<pubDate>Tue, 16 Dec 2025 16:30:00 +0100</pubDate>
			<guid>https://docu10.ilias.de/go/blog/15821/894</guid>
			
			
		</item>
		
		<item>
			<title>ILIAS 9.16</title>
			<link>https://docu10.ilias.de/go/blog/15821/895</link>
			<description><![CDATA[<p class="ilc_Paragraph ilc_text_block_Standard">Following 8 security issues have been resolved:<br/><br/>0046023: SOAP: Unauthorized function calls<br/>0046024: SOAP: Unauthorized data exposure<br/>0046025: SOAP: Missing source permission check<br/>0046496: ilServer: Apache Tika multiple XXE vulnerabilities<br/>0045883: BackgroundTasks: Missind CSRF token for two commands in ilBTControllerGUI<br/>0045884: BackgroundTasks: Open redirect in ilBTControllerGUI<br/>0045900: BackgroundTasks: Unauthorized deletion of tasks<br/>0045905: Repository: Stored XSS via SVG file upload of custom icons</p><div style="clear:both;"></div>]]></description>
			<pubDate>Tue, 16 Dec 2025 16:15:00 +0100</pubDate>
			<guid>https://docu10.ilias.de/go/blog/15821/895</guid>
			
			
		</item>
		
		<item>
			<title>ILIAS 8.26</title>
			<link>https://docu10.ilias.de/go/blog/15821/896</link>
			<description><![CDATA[<p class="ilc_Paragraph ilc_text_block_Standard">Following 4 security issues have been resolved:<br/><br/>0045883: BackgroundTasks: Missind CSRF token for two commands in ilBTControllerGUI<br/>0045884: BackgroundTasks: Open redirect in ilBTControllerGUI<br/>0045900: BackgroundTasks: Unauthorized deletion of tasks<br/>0045905: Repository: Stored XSS via SVG file upload of custom icons</p><div style="clear:both;"></div>]]></description>
			<pubDate>Tue, 16 Dec 2025 16:00:59 +0100</pubDate>
			<guid>https://docu10.ilias.de/go/blog/15821/896</guid>
			
			
		</item>
		
		<item>
			<title>ILIAS 10.3</title>
			<link>https://docu10.ilias.de/go/blog/15821/888</link>
			<description><![CDATA[<p class="ilc_Paragraph ilc_text_block_Standard">Following 6 security issues have been resolved:<br/><br/>0045738: Unauthenticated Remote Code Execution<br/>0045898: Wiki: Unauthorized Access to LTI Settings<br/>0045899: ilUIPluginRouterGUI: Unauthorized function calls<br/>0045910: fix: Verification of LTI Result Service Calls<br/>0045897: MediaPool: Open/Unvalidated Redirect<br/>0045975: SOAP: Unauthorized function calls<br/><br/><br/></p><div style="clear:both;"></div>]]></description>
			<pubDate>Tue, 04 Nov 2025 17:00:00 +0100</pubDate>
			<guid>https://docu10.ilias.de/go/blog/15821/888</guid>
			
			
		</item>
		
		<item>
			<title>ILIAS 9.15</title>
			<link>https://docu10.ilias.de/go/blog/15821/887</link>
			<description><![CDATA[<p class="ilc_Paragraph ilc_text_block_Standard">Following 6 security issues have been resolved:<br/><br/>0045738: Unauthenticated Remote Code Execution<br/>0045898: Wiki: Unauthorized Access to LTI Settings<br/>0045899: ilUIPluginRouterGUI: Unauthorized function calls<br/>0045938: Query UI: Known vulnerability in version 1.13.1 (XSS)<br/>0045897: MediaPool: Open/Unvalidated Redirect<br/>0045975: SOAP: Unauthorized function calls<br/></p><div style="clear:both;"></div>]]></description>
			<pubDate>Tue, 04 Nov 2025 16:45:00 +0100</pubDate>
			<guid>https://docu10.ilias.de/go/blog/15821/887</guid>
			
			
		</item>
		
		<item>
			<title>ILIAS 8.25</title>
			<link>https://docu10.ilias.de/go/blog/15821/886</link>
			<description><![CDATA[<p class="ilc_Paragraph ilc_text_block_Standard">Following 4 security issues have been resolved:<br/><br/>0045738: Unauthenticated Remote Code Execution<br/>0045898: Wiki: Unauthorized Access to LTI Settings<br/>0045899: ilUIPluginRouterGUI: Unauthorized function calls<br/>0045897: MediaPool: Open/Unvalidated Redirect<br/><br/></p><div style="clear:both;"></div>]]></description>
			<pubDate>Tue, 04 Nov 2025 16:30:00 +0100</pubDate>
			<guid>https://docu10.ilias.de/go/blog/15821/886</guid>
			
			
		</item>
		
		<item>
			<title>ILIAS 10.2</title>
			<link>https://docu10.ilias.de/go/blog/15821/882</link>
			<description><![CDATA[<p class="ilc_Paragraph ilc_text_block_Standard">Following 9 security issues have been resolved:<br/><br/>0045633: Test &amp; Assessment: Stored XSS in Question Pool<br/>0045635: WOPI: Open Redirect<br/>0045738: Certificate: Unauthenticated Remote Code Execution<br/>0045744: Test &amp; Assessment: Unsafe operation during import<br/>0045745: Certificate: Unsanitized SVG Files in Import<br/>0045752: Test &amp; Assessment: Authenticated RCE über unsichere Deserialisierung<br/>0045776: Rating: Missing CSRF Token in Rating request<br/>0045777: Data Collection: Open/Unvalidated Redirect in DataCollections<br/>0045801: Test &amp; Assessment: Fixes Wrong Access Right Check and Route From Test to Question</p><div style="clear:both;"></div>]]></description>
			<pubDate>Tue, 23 Sep 2025 16:05:00 +0200</pubDate>
			<guid>https://docu10.ilias.de/go/blog/15821/882</guid>
			
			
		</item>
		
		<item>
			<title>ILIAS 9.14</title>
			<link>https://docu10.ilias.de/go/blog/15821/881</link>
			<description><![CDATA[<p class="ilc_Paragraph ilc_text_block_Standard">Following 9 security issues have been resolved:<br/><br/>0045633: Test &amp; Assessment: Stored XSS in Question Pool<br/>0045635: WOPI: Open Redirect<br/>0045738: Certificate: Unauthenticated Remote Code Execution<br/>0045744: Test &amp; Assessment: Unsafe operation during import<br/>0045745: Certificate: Unsanitized SVG Files in Import<br/>0045752: Test &amp; Assessment: Authenticated RCE über unsichere Deserialisierung<br/>0045776: Rating: Missing CSRF Token in Rating request<br/>0045777: Data Collection: Open/Unvalidated Redirect in DataCollections<br/>0045801: Test &amp; Assessment: Fixes Wrong Access Right Check and Route From Test to Question</p><div style="clear:both;"></div>]]></description>
			<pubDate>Tue, 23 Sep 2025 16:00:00 +0200</pubDate>
			<guid>https://docu10.ilias.de/go/blog/15821/881</guid>
			
			
		</item>
		
		<item>
			<title>ILIAS 8.24</title>
			<link>https://docu10.ilias.de/go/blog/15821/880</link>
			<description><![CDATA[<p class="ilc_Paragraph ilc_text_block_Standard">Following 7 security issues have been resolved:<br/><br/>0045633: Test &amp; Assessment: Stored XSS in Question Pool<br/>0045738: Certificate: Unauthenticated Remote Code Execution<br/>0045744: Test &amp; Assessment: Unsafe operation during import<br/>0045745: Certificate: Unsanitized SVG Files in Import<br/>0045752: Test &amp; Assessment: Authenticated RCE über unsichere Deserialisierung<br/>0045776: Rating: Missing CSRF Token in Rating request<br/>0045801: Test &amp; Assessment: Fixes Wrong Access Right Check and Route From Test to Question<br/></p><div style="clear:both;"></div>]]></description>
			<pubDate>Tue, 23 Sep 2025 15:55:00 +0200</pubDate>
			<guid>https://docu10.ilias.de/go/blog/15821/880</guid>
			
			
		</item>
		
		<item>
			<title>ILIAS 10.1</title>
			<link>https://docu10.ilias.de/go/blog/15821/877</link>
			<description><![CDATA[<p class="ilc_Paragraph ilc_text_block_Standard">Following 2 security issues have been resolved:<br/><br/>0045628: [UICore] UICore: Improper validation of CSRF tokens<br/>0045642: [Logging] Logging: Plaintext Passwords in Error Logs<br/><br/></p><div style="clear:both;"></div>]]></description>
			<pubDate>Tue, 26 Aug 2025 16:14:49 +0200</pubDate>
			<guid>https://docu10.ilias.de/go/blog/15821/877</guid>
			
			
		</item>
		
		<item>
			<title>ILIAS 9.13</title>
			<link>https://docu10.ilias.de/go/blog/15821/876</link>
			<description><![CDATA[<p class="ilc_Paragraph ilc_text_block_Standard">Following 2 security issues have been resolved:<br/><br/>0045628: [UICore] UICore: Improper validation of CSRF tokens<br/>0045642: [Logging] Logging: Plaintext Passwords in Error Logs<br/><br/></p><div style="clear:both;"></div>]]></description>
			<pubDate>Tue, 26 Aug 2025 16:09:07 +0200</pubDate>
			<guid>https://docu10.ilias.de/go/blog/15821/876</guid>
			
			
		</item>
		
		<item>
			<title>ILIAS 8.23</title>
			<link>https://docu10.ilias.de/go/blog/15821/875</link>
			<description><![CDATA[<p class="ilc_Paragraph ilc_text_block_Standard">Following 2 security issues have been resolved:<br/><br/>0045628: [UICore] UICore: Improper validation of CSRF tokens<br/>0045642: [Logging] Logging: Plaintext Passwords in Error Logs<br/><br/></p><div style="clear:both;"></div>]]></description>
			<pubDate>Tue, 26 Aug 2025 16:00:50 +0200</pubDate>
			<guid>https://docu10.ilias.de/go/blog/15821/875</guid>
			
			
		</item>
		
		<item>
			<title>ILIAS 9.12</title>
			<link>https://docu10.ilias.de/go/blog/15821/866</link>
			<description><![CDATA[<p class="ilc_Paragraph ilc_text_block_Standard">No security issues have been resolved in this version.</p><div style="clear:both;"></div>]]></description>
			<pubDate>Tue, 15 Jul 2025 16:00:00 +0200</pubDate>
			<guid>https://docu10.ilias.de/go/blog/15821/866</guid>
			
			
		</item>
		
		<item>
			<title>ILIAS 8.22</title>
			<link>https://docu10.ilias.de/go/blog/15821/864</link>
			<description><![CDATA[<p class="ilc_Paragraph ilc_text_block_Standard">Following 5 security issues have been resolved:<br/><br/>0044299: [Weblink] Weblink: Missing permission checks<br/>0044435: [Exercise] Exercise: Unauthorized access<br/>0044469: [Glossary] Glossary: Missing RBAC checks<br/>0044536: [Session (Course &amp; Group)] Session: Missing RBAC checks<br/>0045164: [Media Pools and Media Objects] Media Pool: DoS through infinite loop</p><div style="clear:both;"></div>]]></description>
			<pubDate>Tue, 08 Jul 2025 15:30:00 +0200</pubDate>
			<guid>https://docu10.ilias.de/go/blog/15821/864</guid>
			
			
		</item>
		
		<item>
			<title>ILIAS 9.11</title>
			<link>https://docu10.ilias.de/go/blog/15821/865</link>
			<description><![CDATA[<p class="ilc_Paragraph ilc_text_block_Standard">Following 5 security issues have been resolved:<br/><br/>0044299: [Weblink] Weblink: Missing permission checks<br/>0044435: [Exercise] Exercise: Unauthorized access<br/>0044469: [Glossary] Glossary: Missing RBAC checks<br/>0044536: [Session (Course &amp; Group)] Session: Missing RBAC checks<br/>0045164: [Media Pools and Media Objects] Media Pool: DoS through infinite loop</p><div style="clear:both;"></div>]]></description>
			<pubDate>Tue, 08 Jul 2025 15:30:00 +0200</pubDate>
			<guid>https://docu10.ilias.de/go/blog/15821/865</guid>
			
			
		</item>
		
		<item>
			<title>ILIAS 9.10</title>
			<link>https://docu10.ilias.de/go/blog/15821/849</link>
			<description><![CDATA[<p class="ilc_Paragraph ilc_text_block_Standard">Following 3 security issues have been resolved:<br/><br/>0044343: MediaCast: Unauthorized access<br/>0044426: Learning Module HTML: Unauthorized access <br/>0044559: MediaCast: Missing RBAC checks<br/></p><div style="clear:both;"></div>]]></description>
			<pubDate>Tue, 27 May 2025 17:00:00 +0200</pubDate>
			<guid>https://docu10.ilias.de/go/blog/15821/849</guid>
			
			
		</item>
		
		<item>
			<title>ILIAS 8.21</title>
			<link>https://docu10.ilias.de/go/blog/15821/850</link>
			<description><![CDATA[<p class="ilc_Paragraph ilc_text_block_Standard">Following 2 security issues have been resolved:<br/><br/>0044343: MediaCast: Unauthorized access<br/>0044559: MediaCast: Missing RBAC checks<br/></p><div style="clear:both;"></div>]]></description>
			<pubDate>Tue, 27 May 2025 17:00:00 +0200</pubDate>
			<guid>https://docu10.ilias.de/go/blog/15821/850</guid>
			
			
		</item>
		
		<item>
			<title>ILIAS 8.20</title>
			<link>https://docu10.ilias.de/go/blog/15821/847</link>
			<description><![CDATA[<p class="ilc_Paragraph ilc_text_block_Standard">Following security issue has been resolved:<br/><br/>0044426: Learning Module HTML: Unauthorized access to settings form</p><div style="clear:both;"></div>]]></description>
			<pubDate>Thu, 22 May 2025 17:00:00 +0200</pubDate>
			<guid>https://docu10.ilias.de/go/blog/15821/847</guid>
			
			
		</item>
		
		<item>
			<title>ILIAS 9.9</title>
			<link>https://docu10.ilias.de/go/blog/15821/844</link>
			<description><![CDATA[<p class="ilc_Paragraph ilc_text_block_Standard">Due to unfortunate circumstances, there is no security fix in ILIAS 9.9. <br/>Please update to ILIAS 9.10 immediately.<br/><br/>Following security issue has been resolved:<br/><br/>0044426: Learning Module HTML: Unauthorized access to settings form</p><div style="clear:both;"></div>]]></description>
			<pubDate>Tue, 20 May 2025 17:00:00 +0200</pubDate>
			<guid>https://docu10.ilias.de/go/blog/15821/844</guid>
			
			
		</item>
		
		<item>
			<title>ILIAS 8.19</title>
			<link>https://docu10.ilias.de/go/blog/15821/833</link>
			<description><![CDATA[<p class="ilc_Paragraph ilc_text_block_Standard">Following 8 security issues have been resolved:<br/><br/>0040995: Fixed escaping of Title and Author in Tile-View of Objects<br/>0044199: XSS hidden input escaping<br/>0044254: ActiveRecord: Missing escaping<br/>0044255: Bibliographic: Missing input validation<br/>0044342: LearningSequence: Unauthorized access<br/>0044438: Test: Missing RBAC checks<br/>0044441: XSS in Question Titles<br/>0044737: Added Missing RBAC Check in TranslationsGUI</p><div style="clear:both;"></div>]]></description>
			<pubDate>Tue, 01 Apr 2025 17:00:00 +0200</pubDate>
			<guid>https://docu10.ilias.de/go/blog/15821/833</guid>
			
			
		</item>
		
		<item>
			<title>ILIAS 9.8</title>
			<link>https://docu10.ilias.de/go/blog/15821/834</link>
			<description><![CDATA[<p class="ilc_Paragraph ilc_text_block_Standard">Following 10 security issues have been resolved:<br/><br/>0040995: Fixed escaping of Title and Author in Tile-View of Objects<br/>0043900: Fixed escaping of LOM on the info tab and in the editor<br/>0044126: Login Response Improvement: Use generic error message<br/>0044199: XSS hidden input escaping<br/>0044254: ActiveRecord: Missing escaping<br/>0044255: Bibliographic: Missing input validation<br/>0044342: LearningSequence: Unauthorized access<br/>0044438: Test: Missing RBAC checks<br/>0044441: XSS in Question Titles<br/>0044737: Added Missing RBAC Check in TranslationsGUI</p><div style="clear:both;"></div>]]></description>
			<pubDate>Tue, 01 Apr 2025 17:00:00 +0200</pubDate>
			<guid>https://docu10.ilias.de/go/blog/15821/834</guid>
			
			
		</item>
		
	</channel>
</rss>
