PT-2022-10230 · Htmly · Htmly

Wszdhf

·

Published

2022-09-30

·

Updated

2025-05-20

·

CVE-2021-33354

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions htmly versions prior to 2.8.1
Description The issue allows remote attackers to perform arbitrary file deletions via a modified file parameter. This is a Directory Traversal vulnerability, which enables attackers to access files outside the intended directory structure.
Recommendations For versions prior to 2.8.1, update to version 2.8.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the file parameter in affected API endpoints until a patch is available.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2021-33354

Affected Products

Htmly