Record summary

CVE-2021-33807 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Cartadis Gespage through 8.2.1 allows Directory Traversal in gespage/doDownloadData and gespage/webapp/doDownloadData.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHCartadis Gespage 8.2.1 - Directory TraversalCVSS 7.5

Cartadis Gespage through 8.2.1 allows Directory Traversal in gespage/doDownloadData and gespage/webapp/doDownloadData.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access to sensitive files, potential data leakage, and further compromise of the system.

Remediation

Apply the latest security patch or update provided by the vendor to fix the directory traversal vulnerability in Cartadis Gespage 8.2.1.

WeaknessesCWE-22
Authorsdaffainfo
Template tagscve2021cvelfigespagevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:gespage:gespage:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

5