S4E just found a medium-severity finding from http usage detection scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-45917 Scanner

CVE-2022-45917 scanner - Open Redirect vulnerability in ILIAS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-45917
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

ILIAS before 7.16 has an Open Redirect.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

ILIAS, which stands for Integrated Learning, Information, and Collaboration System, is a powerful open-source learning management system that provides a platform for creating and delivering e-Learning content. It is a comprehensive solution that offers a range of features, including course management, user management, content management, assessment, and communication tools. It is widely used in schools, universities, and other educational institutions globally, with more than 7 million users.

Recently, a critical vulnerability was detected in this product, identified as CVE-2022-45917. This Open Redirect vulnerability affects ILIAS versions earlier than 7.16. It allows attackers to hijack user sessions and redirect them to malicious websites, resulting in fraudulent activities such as phishing and malware distribution.

The exploitation of this vulnerability can lead to a significant security breach, compromising sensitive information such as personal data and financial information. It can also give attackers unauthorized access to the system, allowing them to install malware, exfiltrate data, and disrupt the normal functioning of the platform.

s4e.io is a platform that provides reliable and detailed information about vulnerabilities and threats affecting digital assets. By subscribing to their pro features, users can easily and quickly learn about vulnerabilities in their ILIAS installations, as well as other digital assets. With s4e.io, users can get informed about the latest security threats, stay ahead of attackers, and secure their systems against malicious activities.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users of ILIAS should take the following precautions:

  • Upgrade to the latest version of ILIAS, version 7.16, which contains a fix for CVE-2022-45917.
  • Implement a security policy that includes regular software updates, vulnerability scanning, and penetration testing.
  • Educate users on the risks of clicking on links and encourage them to report suspicious activity.
  • Use web application firewalls and intrusion detection/prevention systems to monitor and block attacks targeting the ILIAS platform.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-45917 scanner - Open Redirect vulnerability in ILIAS | S4E