mirror of
https://github.com/0xMarcio/cve.git
synced 2026-02-12 22:53:11 +00:00
21 lines
913 B
Markdown
21 lines
913 B
Markdown
### [CVE-2021-27341](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27341)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
OpenSIS Community Edition version <= 7.6 is affected by a local file inclusion vulnerability in DownloadWindow.php via the "filename" parameter.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://github.com/OS4ED/openSIS-Classic/commit/f78407d5291c686c3f416073dcb9143f3a3d5489#diff-24b751f2072f058259d033016938101f9fa29884ebcc09ce7eb88def3421e5ba
|
|
- https://github.com/OS4ED/openSIS-Classic/issues/158
|
|
- https://github.com/OS4ED/openSIS-Classic/releases
|
|
|
|
#### Github
|
|
- https://github.com/20142995/nuclei-templates
|
|
- https://github.com/cyb3r-w0lf/nuclei-template-collection
|
|
|