CVE-2021-33807
HIGH NUCLEIgespage < 8.2.1 - Path Traversal via doDownloadData Endpoint
Title source: llmExploitation Summary
CVE-2021-33807 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.
Description
Cartadis Gespage through 8.2.1 allows Directory Traversal in gespage/doDownloadData and gespage/webapp/doDownloadData.
Nuclei Templates (1)
Cartadis Gespage 8.2.1 - Directory Traversal
HIGHby daffainfo
References (4)
Core 4
Core References
Third Party Advisory x_refsource_misc
https://www.cartadis.com/gespage-website/
Vendor Advisory x_refsource_misc
https://www.gespage.com
Vendor Advisory x_refsource_confirm
https://support.gespage.com/fr/support/solutions/articles/14000130201-security-advisory-gespage-directory-traversal
Exploit, Third Party Advisory x_refsource_misc
https://www.on-x.com/sites/default/files/on-x_-_security_advisory_-_gespage_-_cve-2021-33807.pdf
Scores
CVSS v3
7.5
EPSS
0.1411
EPSS Percentile
96.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-22
Status
published
Products (1)
gespage/gespage
< 8.2.1
Published
Jul 12, 2021
Tracked Since
Feb 18, 2026