vendor:
FoF Pretty Mail
by:
Chokri Hammedi
6.1
CVSS
HIGH
Local File Inclusion (LFI)
22
CWE
Product Name: FoF Pretty Mail
Affected Version From: 1.1.2002
Affected Version To: 1.1.2002
Patch Exists: NO
Related CWE:
CPE: a:friendsofflarum:pretty_mail:1.1.2
Platforms Tested: Windows XP
2024
FoF Pretty Mail 1.1.2 – Local File Inclusion Vulnerability
FoF Pretty Mail 1.1.2 extension for Flarum is vulnerable to Local File Inclusion (LFI) as it mishandles file paths in email templates. An attacker with administrative privileges can exploit this flaw to include sensitive server files in email content, potentially leading to information disclosure.
Mitigation:
To mitigate this vulnerability, ensure proper input validation and sanitization of file paths in email templates. Limit administrative access and monitor email content for unusual file inclusions.