CVE-2021-39433
BIQS IT Biqs-drive v1.83 Local File Inclusion
Record summary
CVE-2021-39433 has a selected CVSS score of 7.5 (high); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
A local file inclusion (LFI) vulnerability exists in version BIQS IT Biqs-drive v1.83 and below when sending a specific payload as the file parameter to download/index.php. This allows the attacker to read arbitrary files from the server with the permissions of the configured web-user.
Exploitation context
Proofs of concept
1Repository PoCs
GitHubPinkDraconian/CVE-2021-39433Repository PoCby PinkDraconianStars: 5Not analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHBIQS IT Biqs-drive v1.83 Local File InclusionCVSS 7.5
A local file inclusion vulnerability exists in version BIQS IT Biqs-drive v1.83 and below when sending a specific payload as the file parameter to download/index.php. This allows the attacker to read arbitrary files from the server with the permissions of the configured web-user.
Impact
Successful exploitation of this vulnerability can lead to unauthorized access to sensitive files, remote code execution, and potential compromise of the entire system.
Remediation
Upgrade to the latest version of BIQS IT Biqs-drive (v1.84 or higher) which includes a fix for the Local File Inclusion vulnerability.
Source: ProjectDiscovery