PT-2021-23456 · Unknown · Resourcespace

Published

2021-11-15

·

Updated

2024-03-06

·

CVE-2021-41950

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions ResourceSpace versions 9.6 through 9.6 rev 18277
Description A directory traversal issue allows remote unauthenticated attackers to delete arbitrary files on the server via the provider and variant parameters in "pages/ajax/tiles.php". Attackers can delete configuration or source code files, causing the application to become unavailable to all users.
Recommendations For versions 9.6 through 9.6 rev 18277, update to a version after 9.6 rev 18277 to resolve the issue. As a temporary workaround, consider restricting access to the "pages/ajax/tiles.php" endpoint to minimize the risk of exploitation. Avoid using the provider and variant parameters in the affected endpoint until the issue is resolved.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BIT-RESOURCESPACE-2021-41950
CVE-2021-41950

Affected Products

Resourcespace