CVE-2021-40651
OpenSIS 8.0 'modname' - Directory Traversal
Record summary
CVE-2021-40651 has a selected CVSS score of 6.5 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
OS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), which can disclose arbitrary file from the server's filesystem as long as the application has access to the file.
Exploitation context
Proofs of concept
1Catalogued exploits
ExploitDBOpenSIS 8.0 'modname' - Directory TraversalExploitDB exploitby Eric SalarioNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMOS4Ed OpenSIS Community 8.0 - Local File InclusionCVSS 6.5
OS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), which can disclose arbitrary file from the server's filesystem as long as the application has access to the file.
Impact
Authenticated attackers can read arbitrary files from the server including /etc/passwd via path traversal in the modname parameter.
Remediation
Upgrade to OpenSIS Community version 8.1 or later.
Source: ProjectDiscovery