CVE detail
CVE-2020-27191 — CVE-2020-27191
Published 2020-11-16 · Modified 2026-06-17 · Vendor lionwiki · Product lionwiki · Source nvd
HIGH
severity
CVSS-derived band
0.0959
EPSS probability
exploitation probability, 30d
95.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
LionWiki before 3.2.12 allows an unauthenticated user to read files as the web server user via crafted string in the index.php f1 variable, aka Local File Inclusion. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References