CVE-2021-47724
MEDIUMSTVS ProVision 5.9.10 - Authenticated Path Traversal via Archive Download Files Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-47724. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates an authenticated local file inclusion (LFI) vulnerability in STVS ProVision 5.9.10 and earlier versions. The vulnerability allows an authenticated attacker to disclose arbitrary files by manipulating the 'files' parameter in the archive download script (archive.rb).
Description
STVS ProVision 5.9.10 contains a path traversal vulnerability that allows authenticated attackers to access arbitrary files by manipulating the files parameter in the archive download functionality. Attackers can send GET requests to /archive/download with directory traversal sequences to read sensitive system files like /etc/passwd.
Exploits (1)
This exploit demonstrates an authenticated local file inclusion (LFI) vulnerability in STVS ProVision 5.9.10 and earlier versions. The vulnerability allows an authenticated attacker to disclose arbitrary files by manipulating the 'files' parameter in the archive download script (archive.rb).
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N