A directory traversal issue in ResourceSpace 9.6 before 9.6 rev 18277 allows remote unauthenticated attackers to delete arbitrary files on the ResourceSpace server via the provider and variant parameters in pages/ajax/tiles.php. Attackers can delete configuration or source code files, causing the application to become unavailable to all users.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T03:22:25.694Z
Reserved: 2021-10-04T00:00:00
Link: CVE-2021-41950
No data.
Status : Modified
Published: 2021-11-15T16:15:10.277
Modified: 2024-11-21T06:26:59.590
Link: CVE-2021-41950
No data.
OpenCVE Enrichment
No data.
Weaknesses