ILIAS before 9.24, 10.x before 10.12 and 11.x before 11.5 contains an argument injection vulnerability in assImagemapQuestionGUI that allows question authors to inject ImageMagick convert options via uploaded image filenames. Attackers can embed tab-separated options, which escapeshellcmd() does not neutralise, to write a PHP file under the web root and achieve remote code execution.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 08 Oct 2026 14:30:00 +0000
Thu, 08 Oct 2026 14:15:00 +0000
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-08T14:23:00.212Z
Reserved: 2026-10-08T14:06:00.711Z
Link: CVE-2026-107639
No data.
Status : Deferred
Published: 2026-10-08T15:17:47.117
Modified: 2026-10-08T15:17:47.273
Link: CVE-2026-107639
No data.
OpenCVE Enrichment
Updated: 2026-10-08T16:00:06Z
Weaknesses