S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Feb 18, 2024

CVE-2021-40651 Scanner

Detects 'Local File Inclusion (LFI)' vulnerability in OS4Ed OpenSIS Community affects v. 8.0.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.4k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-40651
6.5
CVSS

OS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), which can disclose arbitrary file from the server's filesystem as long as the application has access to the file.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Vulnerability Overview

The issue exists due to improper handling of the modname parameter in Modules.php. By manipulating the parameter with directory traversal sequences, an attacker can include and execute arbitrary files from the server's filesystem.

Vulnerability Details

Exploiting the vulnerability involves crafting a malicious request to Modules.php with a modified modname parameter that includes directory traversal characters (../). This can lead to unauthorized access to sensitive files like /etc/passwd, providing attackers with valuable system information and potentially facilitating further attacks.

Possible Effects

Exploitation of this LFI vulnerability could result in:

  • Disclosure of sensitive files and data stored on the server.
  • Gaining insights into system configuration and installed software for further targeted attacks.

Why Choose S4E

At S4E, we are committed to providing top-notch vulnerability scanning solutions tailored to detect and mitigate threats like CVE-2021-40651 efficiently. By joining our platform, you gain access to:

  • Comprehensive vulnerability scanning tools.
  • Expert guidance for remediation strategies.
  • Continuous updates on emerging security threats. Our platform empowers you to strengthen your cybersecurity posture effectively and proactively defend against evolving cyber threats.

References

Solution Advice
  • Update Immediately: Ensure OpenSIS is updated beyond version 8.0 to mitigate this vulnerability.
  • Access Controls: Tighten access controls and permissions to limit file access through the web application.
  • Regular Monitoring: Implement monitoring for unusual access patterns or exploitation attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.