PT-2026-3032 · Unknown · Oliver Library Server
CVE-2021-47755
·
Publicado
2026-01-15
·
Atualizado
2026-01-20
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Oliver Library Server version 5
Description
An unauthenticated attacker can access arbitrary system files. This is possible due to unsanitized input in the
FileServlet endpoint. The vulnerability is triggered by manipulating the fileName parameter, allowing download of sensitive files from the server's filesystem.Recommendations
Apply input sanitization to the
fileName parameter in the FileServlet endpoint.Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Oliver Library Server