Vulnerability Description
An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8. On the admin portal of the web application, there is a functionality at diagzip.asp that allows anyone to export tables of a database.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mutare | Voice | >= 3.2.6, < 3.3.8 |
References
- https://www.mutare.com/security-adv-mutare-2021-003-mutare-voice/Vendor Advisory
- https://www.mutare.com/security-adv-mutare-2021-003-mutare-voice/Vendor Advisory
FAQ
What is CVE-2021-27235?
CVE-2021-27235 is a vulnerability with a CVSS score of 4.9 (MEDIUM). An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8. On the admin portal of the web application, there is a functionality at diagzip.asp that allows anyone to export tables of a database.
How severe is CVE-2021-27235?
CVE-2021-27235 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-27235?
Check the references section above for vendor advisories and patch information. Affected products include: Mutare Voice.