CVE-2021-29398

Directory traversal in /northstar/Common/NorthFileManager/fileManagerObjects.jsp Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to browse and list the directories across the entire filesystem of the host of the web application.
References
Link Resource
https://ardent-security.com/en/advisory/asa-2021-06/ Third Party Advisory
https://Ardent-Security.com Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:globalnorthstar:northstar_club_management:6.3:*:*:*:*:*:*:*

Information

Published : 2022-02-04 11:15

Updated : 2022-02-08 12:15


NVD link : CVE-2021-29398

Mitre link : CVE-2021-29398


JSON object : View

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Advertisement

dedicated server usa

Products Affected

globalnorthstar

  • northstar_club_management