CVE-2021-47921

MEDIUM

Free Photo & Video Vault <0.0.2 - Path Traversal

Title source: llm
STIX 2.1

Description

Free Photo & Video Vault 0.0.2 contains a directory traversal web vulnerability that allows remote attackers to manipulate application path requests and access sensitive system files. Attackers can exploit the vulnerability without privileges to retrieve environment variables and access unauthorized system paths.

Scores

CVSS v3 6.5
EPSS 0.0069
EPSS Percentile 48.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
Author: Scott Ferreira/Free Photo & Video Vault - WiFi Transfe‪r 0.0.2
Published Feb 01, 2026
Tracked Since Feb 18, 2026