{"id":"CVE-2020-36944","details":"ILIAS Learning Management System 4.3 contains a server-side request forgery vulnerability that allows attackers to read local files through portfolio PDF export functionality. Attackers can inject a script that uses XMLHttpRequest to retrieve local file contents when the portfolio is exported to PDF.","modified":"2026-07-08T17:56:26.097823Z","published":"2026-01-28T18:16:45.727Z","references":[{"type":"WEB","url":"https://www.ilias.de/"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/ilias-learning-management-system-ssrf"},{"type":"PACKAGE","url":"https://github.com/ILIAS-eLearning/ILIAS"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/49148"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ilias-elearning/ilias","events":[{"introduced":"72579547883384ea1df3724b1605cab4164fe02e"},{"last_affected":"1a4b8f71a3b4f5f753d847fa87258a214baeef06"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.3.0"},{"last_affected":"5.1.0"}]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-36944.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}