PT-2021-23853 · Unknown · Servermanagement

Ghost

·

Published

2021-11-12

·

Updated

2021-11-16

·

CVE-2021-43493

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ServerManagement master branch as of commit 49491cc6f94980e6be7791d17be947c27071eb56
Description The issue is a directory traversal vulnerability that can be used to extract credentials, which can then be used to execute code.
Recommendations For the affected ServerManagement master branch as of commit 49491cc6f94980e6be7791d17be947c27071eb56, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-43493

Affected Products

Servermanagement