S4E just found a medium-severity finding from online expired ssl certificate checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2020-27191 Scanner

CVE-2020-27191 scanner - Local File Inclusion (LFI) vulnerability in LionWiki

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.7k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-27191
7.5
CVSS

LionWiki before 3.2.12 allows an unauthenticated user to read files as the web server user via crafted string in the index.php f1 variable, aka Local File Inclusion. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

LionWiki is a lightweight, open-source content management system that allows users to create and manage their own wiki websites. Developed in PHP, this software package is easy to install, lightweight, and doesn't require a database. LionWiki is used by individuals, businesses, schools, and non-profit organizations to create wikis and share knowledge across their community.

Recently, a vulnerability has been detected in LionWiki – CVE-2020-27191. This Local File Inclusion allows an unauthenticated user to read files as the web server user by injecting a crafted string in the index.php f1 variable. This vulnerability only affects older versions of LionWiki that are no longer supported by the maintainer. In other words, those who are using the latest version of the software are not affected by this vulnerability.

If this vulnerability is exploited, the unauthenticated user can read and access sensitive information stored on the server. This includes important data such as user credentials, personal information, and confidential documents. It also opens up the possibility for hackers to execute arbitrary code that can have damaging consequences like file deletion, data corruption and more.

In conclusion, vulnerabilities in digital assets can have far-reaching consequences, and it is important to stay vigilant and take appropriate steps to protect against them. s4e.io is a powerful platform that provides a comprehensive suite of pro features to identify and mitigate vulnerabilities in your digital assets quickly and easily. By using this platform, individuals and businesses can keep their data safe from new vulnerabilities like CVE-2020-27191 and other threats.

 

REFERENCES

Solution Advice

Luckily, steps can be taken to protect against this vulnerability. These include:

  • Upgrade to the latest version of LionWiki.
  • Limit access to the LionWiki admin panel to authorized individuals.
  • Implement a web application firewall (WAF) that has LFI protection.
  • Use a Content Security Policy (CSP) to control the types of resources that can be loaded on the server.
  • Conduct regular vulnerability assessments and penetration testing.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-27191 scanner - Local File Inclusion (LFI) vulnerability in LionWiki | S4E