nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-24571 CVE-2020-24571
HIGHNuclei
NexusDB <4.50.23 - Local File Inclusion
Record summary
CVE-2020-24571 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
NexusQA NexusDB before 4.50.23 allows the reading of files via ../ directory traversal.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHNexusDB <4.50.23 - Local File InclusionCVSS 7.5
NexusQA NexusDB before 4.50.23 allows the reading of files via ../ directory traversal and local file inclusion.
Impact
An attacker can exploit this vulnerability to access sensitive information, such as configuration files, credentials, or other sensitive data.
Remediation
Upgrade NexusDB to version 4.50.23 or later to mitigate the LFI vulnerability.
WeaknessesCWE-22
Authorspikpikcu
Template tagscvecve2020nexusdblfivuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:nexusdb:nexusdb:*:*:*:*:*:*:*:*
https://www.nexusdb.com/mantis/bug_view_advanced_page.php?bug_id=2371 https://nvd.nist.gov/vuln/detail/CVE-2020-24571 https://github.com/ARPSyndicate/kenzer-templates https://github.com/HimmelAward/Goby_POC https://github.com/StarCrossPortal/scalpel
Source: ProjectDiscovery
References
2nexusdb.com
https://www.nexusdb.com/mantis/bug_view_advanced_page.php?bug_id=2371