Record summary

CVE-2020-27191 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

LionWiki before 3.2.12 allows an unauthenticated user to read files as the web server user via crafted string in the index.php f1 variable, aka Local File Inclusion. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHLionWiki <3.2.12 - Local File InclusionCVSS 7.5

LionWiki before 3.2.12 allows an unauthenticated user to read files as the web server user via crafted strings in the index.php f1 variable, aka local file inclusion.

Impact

An attacker can exploit this vulnerability to access sensitive information, such as configuration files, credentials, or other sensitive data.

Remediation

Upgrade LionWiki to version 3.2.12 or later to mitigate the LFI vulnerability.

WeaknessesCWE-22
Authors0x_Akoko
Template tagscve2020cvelionwikilfiossvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:lionwiki:lionwiki:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3