PT-2021-4976 · Adobe · Dreamweaver
Published
2021-02-09
·
Updated
2021-09-08
·
CVE-2021-21055
CVSS v3.1
6.2
Medium
| Vector | AV:P/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Adobe Dreamweaver versions 21.0 and earlier
Adobe Dreamweaver versions 20.2 and earlier
Description
The issue is related to an untrusted search path vulnerability. This could allow an attacker with physical access to the system to replace certain configuration files and dynamic libraries that Dreamweaver references, potentially resulting in information disclosure. The vulnerability is associated with the use of an untrusted search path in the HTML editor.
Recommendations
For Adobe Dreamweaver versions 21.0 and earlier, consider restricting access to configuration files and dynamic libraries to minimize the risk of exploitation.
For Adobe Dreamweaver versions 20.2 and earlier, consider implementing additional security measures to protect against physical access to the system.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dreamweaver