CVE-2020-10560 describes an arbitrary file read vulnerability in Open Source Social Network (OSSN) versions through 5.3. An attacker can leverage a user-controlled file path and weak cryptographic rand() to read any file accessible by the webserver, potentially leading to further compromise. This medium-severity vulnerability (CVSS 5.9) requires a high attack complexity, as the attacker must brute-force a SiteKey to inject into a crafted URL. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit or Nuclei, though it has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.3CPE matchmatch criteria | cpe:2.3:a:opensource-socialnetwork:open_source_social_network:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.