PT-2021-21188 · Unknown · Mik.Starlight

Johannes Eger

+1

·

Published

2021-08-31

·

Updated

2021-09-08

·

CVE-2021-36233

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions MIK.starlight version 7.9.5.24363
Description The issue allows an authenticated attacker to read arbitrary files from the filesystem by specifying the file path, due to the functionality of the AdminGetFirstFileContentByFilePath function.
Recommendations For MIK.starlight version 7.9.5.24363, consider restricting access to the AdminGetFirstFileContentByFilePath function to minimize the risk of exploitation.

Exploit

Fix

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-36233

Affected Products

Mik.Starlight