CVE-2020-29227
Car Rental Management System index.php Vulnerability
Record summary
CVE-2020-29227 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
An issue was discovered in Car Rental Management System 1.0. An unauthenticated user can perform a file inclusion attack against the /index.php file with a partial filename in the "page" parameter, to cause local file inclusion resulting in code execution.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 12, 2021 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
car_rental_management_systemBrowse car_rental_management_system_project / car_rental_management_system | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALCar Rental Management System 1.0 - Local File InclusionCVSS 9.8
Car Rental Management System 1.0 allows an unauthenticated user to perform a file inclusion attack against the /index.php file with a partial filename in the "page" parameter, leading to code execution.
Impact
An attacker can exploit this vulnerability to read sensitive files on the server, potentially leading to unauthorized access or information disclosure.
Remediation
Apply the latest patch or update provided by the vendor to fix the LFI vulnerability in the Car Rental Management System 1.0.
Source: ProjectDiscovery