CVE-2021-42261
Last modified
CVE-2021-42261 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Revisor Video Management System (VMS) before 2.0.0 has a directory traversal vulnerability. Successful exploitation could allow an attacker to traverse the file system to access files or directories that are outside of restricted directory on the remote server. EPSS estimates a 2.21% chance of exploitation in the next 30 days.
Description
Revisor Video Management System (VMS) before 2.0.0 has a directory traversal vulnerability. Successful exploitation could allow an attacker to traverse the file system to access files or directories that are outside of restricted directory on the remote server. This could lead to the disclosure of sensitive data on the vulnerable server.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Revisorlab | Video Management System | < 2.0.0 |
References
- https://github.com/jet-pentest/CVE-2021-42261Third Party Advisory
- https://revisorlab.com/Vendor Advisory
- https://github.com/jet-pentest/CVE-2021-42261Third Party Advisory
- https://revisorlab.com/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-42261?
How severe is CVE-2021-42261?
How do I fix CVE-2021-42261?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-42254BeyondTrust Privilege Management prior to version 21.6 creat…7.8
- CVE-2021-42255AppGuard Enterprise before 6.7.100.1 creates a Temporary Fil…7.8
- CVE-2021-42257check_smart before 6.9.1 allows unintended drive access by a…7.1
- CVE-2021-42258BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 al…9.8
- CVE-2021-4226RSFirewall tries to identify the original IP address by look…9.8
- CVE-2021-42260TinyXML through 2.6.2 has an infinite loop in TiXmlParsingDa…7.5
- CVE-2021-42262An issue was discovered in Softing OPC UA C++ SDK before 5.7…6.5
- CVE-2021-42263Adobe Premiere Pro 15.4.1 (and earlier) is affected by a Nul…5.5
- CVE-2021-42264Adobe Premiere Pro 15.4.1 (and earlier) is affected by a Nul…5.5
- CVE-2021-42265Adobe Premiere Pro versions 22.0 (and earlier) and 15.4.2 (a…5.5
- CVE-2021-42266Adobe Animate version 21.0.9 (and earlier) is affected by a …7.8
- CVE-2021-42267Adobe Animate version 21.0.9 (and earlier) is affected by a …7.8
Are you affected by CVE-2021-42261?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
