CVE-2021-47724
EUVD-2021-3472409.12.2025, 21:15
STVS ProVision 5.9.10 contains a path traversal vulnerability that allows authenticated attackers to access arbitrary files by manipulating the files parameter in the archive download functionality. Attackers can send GET requests to /archive/download with directory traversal sequences to read sensitive system files like /etc/passwd.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| stvs | provision | 5.5 |
| stvs | provision | 5.6 |
| stvs | provision | 5.7 |
| stvs | provision | 5.8.6 |
| stvs | provision | 5.9.0 |
| stvs | provision | 5.9.1 |
| stvs | provision | 5.9.7 |
| stvs | provision | 5.9.9 |
| stvs | provision | 5.9.10 |
𝑥
= Vulnerable software versions