Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-39180

28
FAUCET Score

CVE-2021-39180 is a path traversal vulnerability in OpenOLAT versions prior to 15.3.18, 15.5.3, and 16.0.0. An authenticated user can upload a specially crafted ZIP file to overwrite arbitrary files writable by the application server, potentially leading to data corruption, configuration file modification, or even remote code execution under specific server configurations. With a CVSS score of 8.8 (High), this vulnerability poses a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the potential for severe consequences necessitates prompt patching.

Impacted Technologies

VendorProductVersion(s)CPE
< 15.3.18CPE matchmatch criteria
cpe:2.3:a:frentix:openolat:*:*:*:*:*:*:*:*
>= 15.4.0, < 15.5.3CPE matchmatch criteria
cpe:2.3:a:frentix:openolat:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.1HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.44%
Probability of exploitation in next 30 days
EPSS Percentile
82.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0244 is in the 81st percentile among its peer group of 17,844 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

github.com / OpenOLAT/OpenOLAT/commit/2cf73c972e23ccd69cc1e103e43c2c8253571d3e
PatchThird Party Advisory
github.com / OpenOLAT/OpenOLAT/commit/5668a41ab3f1753102a89757be013487544279d5
PatchThird Party Advisory
github.com / OpenOLAT/OpenOLAT/commit/699490be8e931af0ef1f135c55384db1f4232637
PatchThird Party Advisory
github.com / OpenOLAT/OpenOLAT/security/advisories/GHSA-x95v-2pgj-9x8j
Third Party Advisory
jira.openolat.org / browse/OO-5549
Permissions RequiredVendor Advisory