Skip to main content

CVE-2022-45918

6.5
MEDIUMCVSS v3.1 Base Score
1.18%
LOW RiskEPSS (64th percentile)

ILIAS before 7.16 allows External Control of File Name or Path.

Published: 12/7/2022
Modified: 6/17/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS Score (Exploitation Probability)

1.18%LOW Exploitation Risk
64th percentile

This vulnerability has a 1.18% probability of being exploited in the next 30 days, ranking higher than 64% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-610)

CVE-2025-11341HIGH 7.3

A security flaw has been discovered in Jinher OA up to 2.0. This affects an unknown function of the file /c6/Jhsoft.Web.module/eformaspx/WebDesign.aspx/?type=SystemUserInfo&style=1. Performing manipulation results in xml external entity reference. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited.

10/6/2025
CVE-2025-11140HIGH 7.3

A vulnerability was identified in Bjskzy Zhiyou ERP up to 11.0. Affected by this vulnerability is the function openForm of the component com.artery.richclient.RichClientService. Such manipulation of the argument contentString leads to xml external entity reference. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

9/29/2025
CVE-2025-11035MEDIUM 6.3

A vulnerability was determined in Jinher OA 2.0. The impacted element is an unknown function of the file /c6/Jhsoft.Web.module/ToolBar/ManageWord.aspx/?text=GetUrl&style=1. This manipulation causes xml external entity reference. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.

9/26/2025
CVE-2025-10816HIGH 7.3

A security flaw has been discovered in Jinher OA 2.0. This affects an unknown part of the file /c6/Jhsoft.Web.module/ToolBar/GetWordFileName.aspx/?text=GetUrl&style=add of the component XML Handler. Performing manipulation results in xml external entity reference. The attack may be initiated remotely. The exploit has been released to the public and may be exploited.

9/22/2025
CVE-2025-10092HIGH 7.3

A vulnerability was found in Jinher OA up to 1.2. This impacts an unknown function of the file /c6/Jhsoft.Web.projectmanage/TaskManage/AddTask.aspx/?Type=add of the component XML Handler. The manipulation results in xml external entity reference. The attack can be executed remotely. The exploit has been made public and could be used.

9/8/2025

Similar SeverityMEDIUM