PT-2021-22585 · Biqs It · Biqs-Drive

Pinkdraconian

·

Published

2021-10-04

·

Updated

2021-10-12

·

CVE-2021-39433

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: BIQS IT Biqs-drive versions 1.83 and below
Description: A local file inclusion (LFI) issue exists when sending a specific payload as the file parameter to the "download/index.php" endpoint. This allows an attacker to read arbitrary files from the server with the permissions of the configured web-user.
Recommendations: For BIQS IT Biqs-drive versions 1.83 and below, consider disabling access to the "download/index.php" endpoint until a patch is available. As a temporary workaround, restrict the file parameter to prevent arbitrary file reading.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-39433

Affected Products

Biqs-Drive