CVE-2023-29919
contec solarview_compact Incorrect Default Permissions
Record summary
CVE-2023-29919 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because texteditor.php is not restricted.
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
solarview_compactBrowse contec / solarview_compact | VulnCheck | Version data not supplied | |
Proofs of concept
1Repository PoCs
GitHubxiaosed/CVE-2023-29919Repository PoCby xiaosedStars: 0Not analyzed1 file
Nuclei templates
1ProjectDiscoveryCRITICALSolarView Compact <= 6.00 - Local File InclusionCVSS 9.1
There is an arbitrary read file vulnerability in SolarView Compact 6.00 and below, attackers can bypass authentication to read files through texteditor.php
Impact
An attacker can exploit this vulnerability to read sensitive files on the server, potentially leading to unauthorized access or information disclosure.
Remediation
Upgrade to a patched version of SolarView Compact or apply the vendor-provided security patch to mitigate the LFI vulnerability.
Source: ProjectDiscovery