CVE-2021-36471: Path Traversal
Directory Traversal vulnerability in AdminLTE 3.1.0 allows remote attackers to gain escalated privilege and view sensitive information via /admin/index2.html, /admin/index3.html URIs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-36471?
The severity of CVE-2021-36471 is critical (9.8 out of 10).
How does the Directory Traversal vulnerability in AdminLTE 3.1.0 occur?
The Directory Traversal vulnerability in AdminLTE 3.1.0 occurs when remote attackers manipulate the /admin/index2.html and /admin/index3.html URIs to gain escalated privilege and view sensitive information.
How can an attacker exploit the Directory Traversal vulnerability in AdminLTE 3.1.0?
An attacker can exploit the Directory Traversal vulnerability in AdminLTE 3.1.0 by crafting malicious requests to access files outside the intended directory structure.
Is there a fix for CVE-2021-36471?
Yes, updating to a version of AdminLTE beyond 3.1.0 will fix the Directory Traversal vulnerability.
Where can I find more information about CVE-2021-36471?
You can find more information about CVE-2021-36471 on the following link: [https://gist.github.com/cybersaki/31ffe679a5552c1047164e3a5b01c2fd](https://gist.github.com/cybersaki/31ffe679a5552c1047164e3a5b01c2fd)