Record summary

CVE-2020-24571 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

NexusQA NexusDB before 4.50.23 allows the reading of files via ../ directory traversal.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHNexusDB <4.50.23 - Local File InclusionCVSS 7.5

NexusQA NexusDB before 4.50.23 allows the reading of files via ../ directory traversal and local file inclusion.

Impact

An attacker can exploit this vulnerability to access sensitive information, such as configuration files, credentials, or other sensitive data.

Remediation

Upgrade NexusDB to version 4.50.23 or later to mitigate the LFI vulnerability.

WeaknessesCWE-22
Authorspikpikcu
Template tagscvecve2020nexusdblfivuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:nexusdb:nexusdb:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2