Record summary

CVE-2020-27467 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

A Directory Traversal vulnerability exits in Processwire CMS before 2.7.1 via the download parameter to index.php.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHProcesswire CMS <2.7.1 - Local File InclusionCVSS 7.5

Processwire CMS prior to 2.7.1 is vulnerable to local file inclusion because it allows a remote attacker to retrieve sensitive files via the download parameter to index.php.

Impact

An attacker can exploit this vulnerability to read sensitive files, execute arbitrary code, or gain unauthorized access to the system.

Remediation

Upgrade Processwire CMS to version 2.7.1 or later to fix the Local File Inclusion vulnerability.

WeaknessesCWE-22
Authors0x_Akoko
Template tagscvecve2020processwirelficmsossvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:processwire:processwire:*:*:*:*:*:*:*:*
Shodan: http.html:"processwire"
FOFA: body="processwire"

Source: ProjectDiscovery

References

2