PT-2021-20081 · Element It · Elements-It Http Commander

Tobias Jäger

·

Published

2021-07-14

·

Updated

2021-07-16

·

CVE-2021-33211

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Elements-IT HTTP Commander version 5.3.3
Description A Directory Traversal issue in the Unzip feature allows remote authenticated users to write files to arbitrary directories via relative paths in ZIP archives.
Recommendations For Elements-IT HTTP Commander version 5.3.3, consider disabling the Unzip feature until a patch is available to prevent exploitation. Restrict access to sensitive directories to minimize the risk of arbitrary file writing.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-33211

Affected Products

Elements-It Http Commander