6.4
CVSSv2

CVE-2021-37425

Published: 10/08/2021 Updated: 18/08/2021
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

Altova MobileTogether Server prior to 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reading mobiletogetherserver.cfg and then reading the certificate and private key.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

altova mobiletogether server

altova mobiletogether server 7.3

Exploits

RedTeam Pentesting discovered a vulnerability in the MobileTogether server which allows users with access to at least one application to read arbitrary, non-binary files from the file system and perform server-side requests The vulnerability can also be used to deny availability of the system As an example, this advisory shows the compromise of t ...