CVE-2021-3915 Information

Description

bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

Reference

https://github.com/bookstackapp/bookstack/commit/ae155d67454d6b9f6c93b2bb457aaa4b2eb1a9ed https://huntr.dev/bounties/fcb65f2d-257a-46f4-bac9-f6ded5649079

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

REQUIRED

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

NONE

Base Score

NONE

Base Severity

5.7

Share on: