CVE Published: 22/12/2021 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: talos |
Vendor: n/a |
Product: Garrett Metal Detectors Status : PUBLISHED
CVE-2021-21908 Description
Specially-crafted command line arguments can lead to arbitrary file deletion. The handle_delete function does not attempt to sanitize or otherwise validate the contents of the [file] parameter (passed to the function as argv[1]), allowing an authenticated attacker to supply directory traversal primitives and delete semi-arbitrary files.