Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:21391
HistoryAug 28, 2019 - 8:16 a.m.

Local File Inclusion (LFI)

2019-08-2808:16:37
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

EPSS

0.007

Percentile

80.9%

opencms-core is vulnerable to local file inclusion (LFI) vulnerability. It is possible because server resources such as: clearhistory.jsp, convertxml.jsp, group_new.jsp, loginmessage.jsp, xmlcontentrepair.jsp, and /system/workplace/admin/history/settings/index.jsp are accessible by the attacker through the management interface.

EPSS

0.007

Percentile

80.9%