CVE-2021-33807 Information

Description

Cartadis Gespage through 8.2.1 allows Directory Traversal in gespage/doDownloadData and gespage/webapp/doDownloadData.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Reference

https://www.cartadis.com/gespage-website/ https://support.gespage.com/fr/support/solutions/articles/14000130201-security-advisory-gespage-directory-traversal https://www.gespage.com https://www.on-x.com/sites/default/files/on-x_-security_advisory-gespage-_cve-2021-33807.pdf

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

NONE

Base Score

NONE

Base Severity

7.5

Share on: