ClanSphere 2011.3 is vulnerable to a local file inclusion...
High severity
Unreviewed
Published
Aug 5, 2025
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Aug 5, 2025
Published to the GitHub Advisory Database
Aug 5, 2025
ClanSphere 2011.3 is vulnerable to a local file inclusion (LFI) flaw due to improper handling of the cs_lang cookie parameter. The application fails to sanitize user-supplied input, allowing attackers to traverse directories and read arbitrary files outside the web root. The vulnerability is further exacerbated by null byte injection (%00) to bypass file extension checks.
References