What the vulnerability does
01Description
Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions.
Explanation of Vulnerability in Simple Terms
Tonda Core versions up to 2.1.2 contain a flaw that allows authenticated users with low privileges to read sensitive data, modify site content, or disrupt service. The vulnerability requires network access and specific conditions to exploit, but does not require user interaction. Site administrators should update to a version newer than 2.1.2 as soon as possible.
What an attacker can do
Read sensitive data, modify site content, or cause service disruption.
Potential impact on your site
Authenticated users can access confidential information, alter content, or crash the site.
Conditions required to exploit
Attacker must have low-level authenticated access to the site.
Key dates
External resources
Related vulnerabilities