Lucene search

K
cvelistKrcertCVELIST:CVE-2021-26629
HistoryApr 26, 2022 - 6:17 p.m.

CVE-2021-26629 tobesoft XPLATFORM Path Traversal Vulnerability

2022-04-2618:17:48
CWE-22
krcert
www.cve.org
4
xplatform
path traversal
vulnerability
cve-2021-26629
arbitrary file creation
xzip archive
decompression
parent path

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.002

Percentile

53.9%

A path traversal vulnerability in XPLATFORM’s runtime archive function could lead to arbitrary file creation. When the .xzip archive file is decompressed, an arbitrary file can be d in the parent path by using the path traversal pattern ‘…\’.

CNA Affected

[
  {
    "platforms": [
      "Windows"
    ],
    "product": "XPLATFORM",
    "vendor": "tobesoft Co.,Ltd",
    "versions": [
      {
        "lessThanOrEqual": "9.2.2.280",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.002

Percentile

53.9%

Related for CVELIST:CVE-2021-26629