6.5
CVE-2021-36233
- EPSS 0.42%
- Veröffentlicht 31.08.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:13:21
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The function AdminGetFirstFileContentByFilePath in MIK.starlight 7.9.5.24363 allows (by design) an authenticated attacker to read arbitrary files from the filesystem by specifying the file path.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Unit4 ≫ Mik.Starlight Version7.9.5.24363
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.42% | 0.612 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
CWE-552 Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.