First published: Mon Jun 28 2021(Updated: )
Adobe RoboHelp Server version 2019.0.9 (and earlier) is affected by a Path Traversal vulnerability when parsing a crafted HTTP POST request. An authenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe RoboHelp Server | ||
Adobe RoboHelp Server | <=2019.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Adobe RoboHelp Server vulnerability is CVE-2021-28588.
The title of this vulnerability is 'Adobe RoboHelp Server folderId Directory Traversal Remote Code Execution Vulnerability'.
The severity of CVE-2021-28588 is critical with a CVSS score of 8.8.
Remote attackers can execute arbitrary code on affected installations of Adobe RoboHelp Server by exploiting this vulnerability.
Adobe RoboHelp Server version 2019.0.9 is affected by this vulnerability.