CVE-2020-27191

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/11/2020
Last modified:
30/11/2020

Description

LionWiki before 3.2.12 allows an unauthenticated user to read files as the web server user via crafted string in the index.php f1 variable, aka Local File Inclusion. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lionwiki:lionwiki:*:*:*:*:*:*:*:* 3.2.12 (excluding)