Path Traversal Vulnerability in STVS ProVision by STVS
CVE-2021-47724
Key Information:
- Vendor
Stvs Sa
- Status
- Vendor
- CVE Published:
- 9 December 2025
Badges
What is CVE-2021-47724?
STVS ProVision 5.9.10 is susceptible to a path traversal vulnerability that enables authenticated attackers to gain access to arbitrary files. By exploiting the archive download functionality, attackers can manipulate the files parameter and issue GET requests with directory traversal sequences, which could allow them to read sensitive system files, such as /etc/passwd. This poses a significant security risk, enabling unauthorized information retrieval from the system.
Affected Version(s)
STVS ProVision 5.9.10 (build 2885-3a8219a)
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
