Record summary

CVE-2021-40651 has a selected CVSS score of 6.5 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

OS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), which can disclose arbitrary file from the server's filesystem as long as the application has access to the file.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBOpenSIS 8.0 'modname' - Directory TraversalExploitDB exploitby Eric SalarioNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMOS4Ed OpenSIS Community 8.0 - Local File InclusionCVSS 6.5

OS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), which can disclose arbitrary file from the server's filesystem as long as the application has access to the file.

Impact

Authenticated attackers can read arbitrary files from the server including /etc/passwd via path traversal in the modname parameter.

Remediation

Upgrade to OpenSIS Community version 8.1 or later.

WeaknessesCWE-22
Authorsctflearner
Template tagscvecve2021lfios4edopensisauthenticatedvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:os4ed:opensis:8.0:*:*:*:community:*:*:*
Shodan: title:"openSIS"
Shodan: http.title:"opensis"
FOFA: title="opensis"
Google: intitle:"opensis"

Source: ProjectDiscovery

References

4