References https://beaglesecurity.com/blog/vulnerability/apache-solr-arbitrary-file-read.html https://s4e.io/tools/apache-solr-arbitrary-file-read-vulnerability-scanner https://pentest-tools.com/vulnerabilities-exploits/apache-solr-881-server-side-request-forgery_2072 https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/apache/apache-solr-file-read.yaml https://threatprotect.qualys.com/2021/03/18/apache-solr-arbitrary-file-read-vulnerability-zero-day/ https://nsfocusglobal.com/apache-solr-arbitrary-file-read-and-ssrf-vulnerability-threat-alert/ https://www.hacefresko.com/posts/unrestricted-access-and-arbitrary-file-read-in-solr-endpoint https://cloud.tencent.com/developer/article/1812009 https://blog.csdn.net/qq_25500649/article/details/117509342 https://github.com/RIZZZIOM/CVE-2021-27905 https://nvd.nist.gov/vuln/detail/CVE-2021-27905
Related Vulnerabilities泛微ecology8 getCptInfoMap 存在SQL注入漏洞PoCCVE-2026-18072: Advanced Responsive Video Embedder 10.8.7/10.8.8 - Hardcoded Backdoor Authentication BypassPoCCVE-2020-29134: TOTVS Fluig <= 1.7.0 - Arbitrary File ReadPoCCVE-2025-51683: mJobTime <= 15.7.2 - Unauthenticated Blind SQL Injection to RCEPoCCVE-2025-57231: Docmost 0.2.1-0.21.0 - Arbitrary File ReadPoCCVE-2026-0561: Shield Security <= 21.0.8 - Unauthenticated Reflected XSSPoCCVE-2026-0650: OpenFlagr <= 1.1.18 - Authentication BypassPoCCVE-2026-0768: Langflow <=1.2.x - Unauthenticated Remote Code Execution via validate_codePoCCVE-2026-1281: Ivanti EPMM <=12.7.0.0 - Unauthenticated Code InjectionPoCCVE-2026-19092: Tutor LMS < 4.0.6 - Unauthenticated Arbitrary PHP Function InvocationPoCCVE-2026-21875: ClipBucket v5 <= 5.5.2 - Unauthenticated Blind SQL InjectionPoCCVE-2026-28141: NextGEN Gallery <= 4.2.3 - Reflected Cross-Site ScriptingPoCCVE-2026-28411: WeGIA < 3.6.5 - Unauthenticated Authentication Bypass via extract()