CVE-2020-27191
LionWiki <3.2.12 - Local File Inclusion
Record summary
CVE-2020-27191 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
LionWiki before 3.2.12 allows an unauthenticated user to read files as the web server user via crafted string in the index.php f1 variable, aka Local File Inclusion. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHLionWiki <3.2.12 - Local File InclusionCVSS 7.5
LionWiki before 3.2.12 allows an unauthenticated user to read files as the web server user via crafted strings in the index.php f1 variable, aka local file inclusion.
Impact
An attacker can exploit this vulnerability to access sensitive information, such as configuration files, credentials, or other sensitive data.
Remediation
Upgrade LionWiki to version 3.2.12 or later to mitigate the LFI vulnerability.
Source: ProjectDiscovery