PT-2021-20159 · Dutchcoders · Transfer.Sh

Ryotak

·

Published

2021-05-24

·

Updated

2024-08-21

·

CVE-2021-33497

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dutchcoders transfer.sh versions prior to 1.2.4
Description The issue allows Directory Traversal, which can be used for deleting files. This can potentially lead to unauthorized access and modification of sensitive data.
Recommendations For versions prior to 1.2.4, update to version 1.2.4 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2021-33497
GHSA-CF55-RQ8X-HM6F
GO-2022-0925

Affected Products

Transfer.Sh