Record summary

CVE-2021-28377 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

ChronoForums 2.0.11 allows av Directory Traversal to read arbitrary files.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMJoomla! ChronoForums 2.0.11 - Local File InclusionCVSS 5.3

Joomla! ChronoForums 2.0.11 avatar function is vulnerable to local file inclusion through unauthenticated path traversal attacks. This enables an attacker to read arbitrary files, for example the Joomla! configuration file which contains credentials.

Impact

The LFI vulnerability can lead to unauthorized access to sensitive files, potentially exposing sensitive information or allowing remote code execution.

Remediation

Update Joomla! ChronoForums to the latest version (2.0.12) or apply the provided patch to fix the LFI vulnerability.

WeaknessesCWE-22
Authors0x_Akoko
Template tagscve2021cvechronoforumslfijoomlachronoenginevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:chronoengine:chronoforums:2.0.11:*:*:*:*:joomla:*:*

Source: ProjectDiscovery

References

2