Vulnerability Database

322,129

Total vulnerabilities in the database

CVE-2020-36944

ILIAS Learning Management System 4.3 contains a server-side request forgery vulnerability that allows attackers to read local files through portfolio PDF export functionality. Attackers can inject a script that uses XMLHttpRequest to retrieve local file contents when the portfolio is exported to PDF.

  • Published: Jan 28, 2026
  • Updated: Feb 10, 2026
  • CVE: CVE-2020-36944
  • Severity: Low
  • Exploit:

CVSS v3:

  • Severity: Low
  • Score: 4
  • AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CWEs: