4.3
CVSSv2

CVE-2020-10560

Published: 30/03/2020 Updated: 21/07/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

An issue exists in Open Source Social Network (OSSN) up to and including 5.3. A user-controlled file path with a weak cryptographic rand() can be used to read any file with the permissions of the webserver. This can lead to further compromise. The attacker must conduct a brute-force attack against the SiteKey to insert into a crafted URL for components/OssnComments/ossn_com.php and/or libraries/ossn.lib.upgrade.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

opensource-socialnetwork open source social network

Github Repositories

CVE-2020-10560 OSSN Arbitrary File Read

CVE-2020-10560 CVE-2020-10560 OSSN Arbitrary File Read For details on how to use this repository refer to techanarchynet/blog/cve-2020-10560-ossn-arbitrary-file-read Starting docker-compose up --build Installing Once the images are running, you can access the install page at 127001 or 1020101 If you want to use BURP do not install on 127001 as you will have is

CVE-2020-10560 Key Recovery (AES) This PoC recovers the site_key for OSSN 53 and above For more information see techanarchynet/blog/cve-2020-10560-ossn-arbitrary-file-read

Python Library for AttackerKB API

AttackerKB API This is a python wrapper around the AttackerKB RESTful API For more details on the API referer to apiattackerkbcom/api-docs/docs Status Installation python3 -m pip install attackerkb-api pip3 install attackerkb-api Usage import json from attackerkb_api import AttackerKB API_KEY = "GET AN API KEY FROM attackerkbcom/" api = Attacke

InfosecBookmarks Organizando os bookmarks que acumulei no Chrome Bug Bounty Methodology WebHacking Recon Tools Awesome Lists Bugs Finding Subdomain Takeover Finding Race Conditions Finding Open Redirections Finding XXE Finding RCE Finding SSRF Finding XSS Finding CSRF Finding SQLi Finding IDOR Mobile Tools CheatSheet Mobile Writeups API Test Labs WriteUps Subdomain