CVE-2021-36233

The function AdminGetFirstFileContentByFilePath in MIK.starlight 7.9.5.24363 allows (by design) an authenticated attacker to read arbitrary files from the filesystem by specifying the file path.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:unit4:mik.starlight:7.9.5.24363:*:*:*:*:*:*:*

Information

Published : 2021-08-31 11:15

Updated : 2021-09-08 11:05


NVD link : CVE-2021-36233

Mitre link : CVE-2021-36233


JSON object : View

CWE
CWE-552

Files or Directories Accessible to External Parties

Advertisement

dedicated server usa

Products Affected

unit4

  • mik.starlight