ZeroHour

CVE-2021-36233

PoC
CVSS 3.1
6.5 medium
EPSS
1%p61
Published
()
Modified
Description

The function AdminGetFirstFileContentByFilePath in MIK.starlight 7.9.5.24363 allows (by design) an authenticated attacker to read arbitrary files from the filesystem by specifying the file path.

Vendors
unit4
Products
mik.starlight
Weakness
CWE-552
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.