CVE-2021-39180 is a path traversal vulnerability in OpenOLAT versions prior to 15.3.18, 15.5.3, and 16.0.0. An authenticated user can upload a specially crafted ZIP file to overwrite arbitrary files writable by the application server, potentially leading to data corruption, configuration file modification, or even remote code execution under specific server configurations. With a CVSS score of 8.8 (High), this vulnerability poses a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the potential for severe consequences necessitates prompt patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 15.3.18CPE matchmatch criteria | cpe:2.3:a:frentix:openolat:*:*:*:*:*:*:*:* | ||
>= 15.4.0, < 15.5.3CPE matchmatch criteria | cpe:2.3:a:frentix:openolat:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.