nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-47755 CVE-2021-47755
HIGH
Oliver Library Server v5 - Arbitrary File Download
Record summary
CVE-2021-47755 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.
Description
Oliver Library Server v5 contains a file download vulnerability that allows unauthenticated attackers to access arbitrary system files through unsanitized input in the FileServlet endpoint. Attackers can exploit the vulnerability by manipulating the 'fileName' parameter to download sensitive files from the server's filesystem.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 15, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Oliver Library ServerBrowse Softlink Education / Oliver Library Server | CVE List | < 8.00.008.053 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBOliver Library Server v5 - Arbitrary File DownloadExploitDB exploitby Mandeep SinghNot analyzed1 file
References
3ExploitDB-50599exploit
https://www.exploit-db.com/exploits/50599 Oliver Library Server Official Product Homepageproduct
https://www.softlinkint.com/product/oliver