PT-2021-20329 · Cartadis · Cartadis Gespage
Olivier Thibault
·
Published
2021-07-12
·
Updated
2021-09-20
·
CVE-2021-33807
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Cartadis Gespage versions 8.2.1 and earlier
Description:
The issue allows Directory Traversal in the "gespage/doDownloadData" and "gespage/webapp/doDownloadData" API endpoints.
Recommendations:
For Cartadis Gespage versions 8.2.1 and earlier, update to a version that fixes the Directory Traversal issue in the
gespage/doDownloadData and gespage/webapp/doDownloadData API endpoints.
As a temporary workaround, consider restricting access to the gespage/doDownloadData and gespage/webapp/doDownloadData API endpoints until a patch is available.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cartadis Gespage