An issue was discovered in PRTG Network Monitor before 21.1.66.1623. By invoking the screenshot functionality with prepared context paths, an attacker is able to verify the existence of certain files on the filesystem of the PRTG's Web server.
References
Link | Resource |
---|---|
https://www.paessler.com/prtg/history/stable#21.1.66.1623 | Release Notes Vendor Advisory |
https://www.paessler.com/prtg/history/stable#21.1.66.1623 | Release Notes Vendor Advisory |
Configurations
History
21 Nov 2024, 05:57
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.paessler.com/prtg/history/stable#21.1.66.1623 - Release Notes, Vendor Advisory |
Information
Published : 2021-03-31 22:15
Updated : 2024-11-21 05:57
NVD link : CVE-2021-27220
Mitre link : CVE-2021-27220
CVE.ORG link : CVE-2021-27220
JSON object : View
Products Affected
paessler
- prtg_network_monitor
CWE