Aller au contenu

Fiche vulnérabilité

CVE-2021-28588 : faille élevée Adobe RoboHelp Server (CVSS 8.8)

Description

Adobe RoboHelp Server version 2019.0.9 (and earlier) is affected by a Path Traversal vulnerability when parsing a crafted HTTP POST request. An authenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
28 juin 2021
Dernière mise à jour
16 sept. 2024

Produits concernés

  • Adobe RoboHelp Server

Références

Rechercher une autre vulnérabilité dans la base CVE