Local File Inclusion Vulnerability in Rendertron by Google Chrome
CVE-2017-18354
7.5HIGH
What is CVE-2017-18354?
Rendertron version 1.0.0 is vulnerable to a Local File Inclusion (LFI) issue, permitting remote attackers to access arbitrary files on the server by exploiting alternative protocols such as 'file://'. This flaw can significantly compromise the security of the server, exposing sensitive data and potentially enabling further attacks.