vendor:
Codiad
by:
TUNISIAN CYBER
7.5
CVSS
HIGH
Local File Disclosure
22
CWE
Product Name: Codiad
Affected Version From: 2.5.2003
Affected Version To: 2.5.2003
Patch Exists: NO
Related CWE: N/A
CPE: a:codiad:codiad
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: PHP
2015
Codiad v2.5.3 – LFI Vulnerability
Pie Register 2.x suffers, from a Local File Disclosure vulnerability. The vulnerability is caused due to the use of user-supplied input without proper validation. This can be exploited to disclose sensitive information by including arbitrary files from local resources via a specially crafted request.
Mitigation:
Input validation should be used to prevent the inclusion of arbitrary files from local resources.