Security Advisory
CVE-2021-40651
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
OS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), which can disclose arbitrary file from the servers filesystem as long as the application has access to the file.