Record summary

CVE-2021-40960 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

Galera WebTemplate 1.0 is affected by a directory traversal vulnerability that could reveal information from /etc/passwd and /etc/shadow.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryCRITICALGalera WebTemplate 1.0 Directory TraversalCVSS 9.8

Galera WebTemplate 1.0 is affected by a directory traversal vulnerability that could reveal information from /etc/passwd and /etc/shadow.

Impact

An attacker can read, modify, or delete sensitive files on the server, potentially leading to unauthorized access, data leakage, or system compromise.

Remediation

Apply the latest security patches or updates provided by the vendor to fix the directory traversal vulnerability in Galera WebTemplate 1.0.

WeaknessesCWE-22
Authorsdaffainfo
Template tagscve2021cvelfigaleravuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:galera:galera_webtemplate:1.0:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3