packetstormsecurity.com
http://packetstormsecurity.com/files/158576/Bio-Star-2.8.2-Local-File-Inclusion.html CVE-2020-15050
HIGHNuclei
Bio Star 2.8.2 - Local File Inclusion
Record summary
CVE-2020-15050 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Proofs of concept
1Catalogued exploits
ExploitDBBio Star 2.8.2 - Local File InclusionExploitDB exploitby SITE TeamNot analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHSuprema BioStar <2.8.2 - Local File InclusionCVSS 7.5
Suprema BioStar before 2.8.2 Video Extension allows remote attackers can read arbitrary files from the server via local file inclusion.
Impact
An attacker can exploit this vulnerability to access sensitive information, such as configuration files, credentials, or other sensitive data stored on the server.
Remediation
Upgrade Suprema BioStar to version 2.8.2 or later to fix the LFI vulnerability.
WeaknessesCWE-22
Authorsgy741
Template tagscvecve2020supremabiostar2packetstormlfisupremaincvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:supremainc:biostar_2:*:*:*:*:*:*:*:*
http://packetstormsecurity.com/files/158576/Bio-Star-2.8.2-Local-File-Inclusion.html https://www.supremainc.com/en/support/biostar-2-pakage.asp https://nvd.nist.gov/vuln/detail/CVE-2020-15050 https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-15050 supremainc.comConfirmation
https://www.supremainc.com/en/support/biostar-2-pakage.asp