First published: Wed Sep 29 2021(Updated: )
OS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), which can disclose arbitrary file from the server's filesystem as long as the application has access to the file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OS4Ed OpenSIS | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-40651.
The severity of CVE-2021-40651 is medium with a CVSS score of 6.5.
The affected software is OS4Ed OpenSIS Community 8.0.
The vulnerability allows for local file inclusion in Modules.php (modname parameter) in OS4Ed OpenSIS Community 8.0, which can expose arbitrary files on the server's filesystem.
To fix the vulnerability, update to the latest version of OS4Ed OpenSIS Community.