← back
CVE-2020-27191

CVE-2020-27191

18Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 9.6%
exploitation probability
9.6%top 5% of all CVEs
observed exploitation
nono source reports it
LionWiki before 3.2.12 allows an unauthenticated user to read files as the web server user via crafted string in the index.php f1 variable, aka Local File Inclusion. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Affected products
n/a · n/a