LionWiki before 3.2.12 allows an unauthenticated user to read files as the web server user via crafted strings in the index.php f1 variable, aka local file inclusion.
id: CVE-2020-27191
info:
name: LionWiki <3.2.12 - Local File Inclusion
author: 0x_Akoko
sever
...