Vulnerability Description
An arbitrary file download vulnerability in Oliver v5 Library Server Versions < 5.00.008.053 via the FileServlet function allows for arbitrary file download by an attacker using unsanitized user supplied input.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Softlinkint | Oliver V5 Library | < 8.00.008.053 |
Related Weaknesses (CWE)
References
- https://www.exploit-db.com/exploits/50599ExploitThird Party AdvisoryVDB Entry
- https://www.softlinkint.com/product/oliver/ProductVendor Advisory
- https://www.exploit-db.com/exploits/50599ExploitThird Party AdvisoryVDB Entry
- https://www.softlinkint.com/product/oliver/ProductVendor Advisory
FAQ
What is CVE-2021-45027?
CVE-2021-45027 is a vulnerability with a CVSS score of 7.5 (HIGH). An arbitrary file download vulnerability in Oliver v5 Library Server Versions < 5.00.008.053 via the FileServlet function allows for arbitrary file download by an attacker using unsanitized user suppl...
How severe is CVE-2021-45027?
CVE-2021-45027 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-45027?
Check the references section above for vendor advisories and patch information. Affected products include: Softlinkint Oliver V5 Library.