CVE-2021-36233

MEDIUM

MIK.starlight 7.9.5.24363 - Info Disclosure

Title source: llm
STIX 2.1

Description

The function AdminGetFirstFileContentByFilePath in MIK.starlight 7.9.5.24363 allows (by design) an authenticated attacker to read arbitrary files from the filesystem by specifying the file path.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0097
EPSS Percentile 57.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-552
Status published
Products (1)
unit4/mik.starlight 7.9.5.24363
Published Aug 31, 2021
Tracked Since Feb 18, 2026