5
CVSSv2

CVE-2021-38146

Published: 22/11/2021 Updated: 23/11/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The File Download API in Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote malicious users to read arbitrary files via absolute path traversal in the SearchString JSON field in /home/download POST data.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wipro holmes 20.4.1

Exploits

Wipro Holmes Orchestrator version 2041 unauthenticated arbitrary file reading proof of concept exploit ...