CVE-2021-41242 is a path traversal vulnerability affecting OpenOlat versions prior to 15.5.12 and 16.0.5. An authenticated attacker with REST API access can exploit this to create directories and write files anywhere on the target system. With a CVSS score of 8.1 (High), the vulnerability has a low attack complexity and can lead to high integrity and availability impacts. While no public exploits or active exploitation have been observed, and community discussion is minimal, a workaround involves disabling or restricting access to the REST module.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 15.5.12CPE matchmatch criteria | cpe:2.3:a:frentix:openolat:*:*:*:*:*:*:*:* | ||
>= 16.0.0, < 16.0.5CPE matchmatch criteria | cpe:2.3:a:frentix:openolat:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.