First published: Sat Nov 13 2021(Updated: )
bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Bookstackapp Bookstack | <21.10.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-3915.
The severity of CVE-2021-3915 is high with a CVSS score of 5.7.
The affected software is bookstack, specifically versions up to and excluding 21.10.3.
The vulnerability allows for unrestricted upload of files with dangerous types, which can lead to potential remote code execution or other malicious activities.
Yes, a fix for this vulnerability has been released. It is recommended to upgrade to version 21.10.3 or later of bookstack to mitigate the risk.