BIT-resourcespace-2021-41950

    Dashboard / Vulnerabilities / BIT-resourcespace-2021-41950

    BIT-resourcespace-2021-41950

    Published: 6 Mar 2024Last Modified: 6 Mar 2024

    Summary:

    Details: A directory traversal issue in ResourceSpace 9.6 before 9.6 rev 18277 allows remote unauthenticated attackers to delete arbitrary files on the ResourceSpace server via the provider and variant parameters in pages/ajax/tiles.php. Attackers can delete configuration or source code files, causing the application to become unavailable to all users.

    Affected packages

    Package

    Name: resourcespace

    Purl: pkg:bitnami/resourcespace

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 9.6.0
    Fixed -None

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    BIT-resourcespace-2021-41950 | CVE-DB