PT-2021-23158 · Mycodo · Mycodo
Haby0
·
Published
2021-10-26
·
Updated
2021-10-27
·
CVE-2021-41185
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Mycodo versions prior to 8.12.7
Description
Mycodo is an environmental monitoring and regulation system. An exploit allows anyone with access to endpoints to download files outside the intended directory. A patch has been applied and a release made.
Recommendations
For versions prior to 8.12.7, upgrade to version 8.12.7.
As a temporary workaround, users may manually apply the changes from the fix commit.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mycodo