Vulnerability Description
In ILIAS through 7.10, lack of verification when changing an email address (on the Profile Page) allows remote attackers to take over accounts.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ilias | Ilias | <= 7.10 |
Related Weaknesses (CWE)
References
- https://medium.com/%40bcksec/in-ilias-through-7-10-620c0de685eeThird Party Advisory
- https://www.bcksec.com/services/Not Applicable
- https://medium.com/%40bcksec/in-ilias-through-7-10-620c0de685eeThird Party Advisory
- https://www.bcksec.com/services/Not Applicable
FAQ
What is CVE-2022-31266?
CVE-2022-31266 is a vulnerability with a CVSS score of 4.3 (MEDIUM). In ILIAS through 7.10, lack of verification when changing an email address (on the Profile Page) allows remote attackers to take over accounts.
How severe is CVE-2022-31266?
CVE-2022-31266 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-31266?
Check the references section above for vendor advisories and patch information. Affected products include: Ilias Ilias.