PT-2021-20081 · Element It · Elements-It Http Commander
Tobias Jäger
·
Published
2021-07-14
·
Updated
2021-07-16
·
CVE-2021-33211
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Elements-IT HTTP Commander version 5.3.3
Description
A Directory Traversal issue in the Unzip feature allows remote authenticated users to write files to arbitrary directories via relative paths in ZIP archives.
Recommendations
For Elements-IT HTTP Commander version 5.3.3, consider disabling the Unzip feature until a patch is available to prevent exploitation. Restrict access to sensitive directories to minimize the risk of arbitrary file writing.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Elements-It Http Commander