vendor:
Openplanning
by:
cr4wl3r
7.5
CVSS
HIGH
RFI/LFI
CWE
Product Name: Openplanning
Affected Version From: Openplanning 1.00
Affected Version To: Openplanning 1.00
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Openplanning 1.00 (RFI/LFI) Multiple File Include Vulnerability
Openplanning 1.00 is vulnerable to a Remote File Inclusion (RFI) and Local File Inclusion (LFI) vulnerability. This vulnerability allows an attacker to include arbitrary files from a remote or local file system, potentially leading to remote code execution.
Mitigation:
To mitigate this vulnerability, it is recommended to apply the latest patch or update from the vendor. Additionally, ensure that input validation and sanitization measures are in place to prevent unauthorized file inclusion.