ZeroHour

CVE-2021-40651

PoC ×3
CVSS 3.1
6.5 medium
EPSS
18%p97
Published
()
Modified
Description

OS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), which can disclose arbitrary file from the server's filesystem as long as the application has access to the file.

Vendors
os4ed
Products
opensis
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.