CVE-2021-33491: Path Traversal
OX App Suite through 7.10.5 allows Directory Traversal via ../ in an OOXML or ODF ZIP archive, because of the mishandling of relative paths in mail addresses in conjunction with auto-configuration DNS records.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-33491?
CVE-2021-33491 is a vulnerability in OX App Suite through 7.10.5 that allows Directory Traversal via ../ in an OOXML or ODF ZIP archive.
How does CVE-2021-33491 affect OX App Suite?
CVE-2021-33491 affects OX App Suite through 7.10.5 by allowing Directory Traversal via ../ in an OOXML or ODF ZIP archive.
What is the severity of CVE-2021-33491?
The severity of CVE-2021-33491 is medium with a severity value of 6.5.
How can CVE-2021-33491 be exploited?
CVE-2021-33491 can be exploited by using ../ in an OOXML or ODF ZIP archive in conjunction with auto-configuration DNS records.
How to fix CVE-2021-33491 in OX App Suite?
To fix CVE-2021-33491 in OX App Suite, it is recommended to update to a version higher than 7.10.5.