An information disclosure vulnerability in ILIAS before 5.3.19, 5.4.12 and 6.0 allows remote authenticated attackers to get the upload data path via a workspace upload.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-23995
Reference (s):
- https://docu.ilias.de/goto_docu_pg_118817_35.html
- https://docu.ilias.de/goto_docu_pg_122177_35.html
- https://docu.ilias.de/goto_docu_pg_124761_35.html
- https://github.com/ILIAS-eLearning/ILIAS/commit/94d9b16010ec3abeae8d2cbb05622ccd999119ad

