S4E just found a high-severity finding from cve-2001-1473 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-41569 Scanner

Detects 'Local File Inclusion (LFI)' vulnerability in SAS/Intrnet affects v. 9.4 build 1520 and earlier.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.2k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-41569
7.5
CVSS

SAS/Intrnet 9.4 build 1520 and earlier allows Local File Inclusion. The samples library (included by default) in the appstart.sas file, allows end-users of the application to access the sample.webcsf1.sas program, which contains user-controlled macro variables that are passed to the DS2CSF macro. Users can escape the context of the configured user-controllable variable and append additional functions native to the macro but not included as variables within the library. This includes a function that retrieves files from the host OS.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

SAS/Intrnet is a software product used for building web applications using SAS programming language. It is used by organizations for creating interactive reports, data visualization, and custom applications. The software allows for rapid development of web-based applications that are deployed locally or on the cloud. Its popularity stems from its ease of use, flexibility, and the ability to integrate with different systems.

One of the vulnerabilities detected in SAS/Intrnet is CVE-2021-41569. This vulnerability arises due to a local file inclusion issue that affects SAS/Intrnet 9.4 build 1520 and earlier. Specifically, the appstart.sas file in the samples library included in the software opens an avenue for end-users to access the sample.webcsf1.sas program. This program contains user-controlled macro variables that are passed to the DS2CSF macro. An attacker can exploit this vulnerability by bypassing the context of the configured user-controllable variable and executing additional functions native to the macro not accounted for in the library.

If exploited, this vulnerability can lead to unauthorized file access, data exfiltration, and remote code execution, which can result in a complete system compromise. Attackers can use the information acquired from the file system to launch further attacks, such as phishing campaigns targeting users or even gaining unauthorized access to other parts of the system.

Those who read this article can quickly learn about vulnerabilities in their digital assets by using the pro features of the s4e.io platform. This platform offers vulnerability scanning, patch management, and threat intelligence services that can help organizations identify, assess, and mitigate risks to their systems. By using this platform, organizations can keep their systems secure and ensure they remain protected against ever-evolving cyber threats.

 

REFERENCES

Solution Advice

Some of the precautions that organizations can take to protect against this vulnerability are: 

  • Update SAS/Intrnet to the latest version that includes a fix for the vulnerability. 
  • Disable the samples library to limit access to vulnerable components. 
  • Monitor and restrict user access to critical files and folders. 
  • Implement access controls using Role-Based Access Control (RBAC) to limit users' privileges. 
  • Use web application firewalls or Intrusion Detection and Prevention Systems (IDPS) to monitor and prevent attacks targeting the vulnerability.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-41569 scanner - Local File Inclusion (LFI) vulnerability in SAS/Intrnet | S4E