Medium severity6.5NVD Advisory· Published Dec 9, 2025· Updated Jun 17, 2026
CVE-2021-47724
CVE-2021-47724
Description
STVS ProVision 5.9.10 contains a path traversal vulnerability that allows authenticated attackers to access arbitrary files by manipulating the files parameter in the archive download functionality. Attackers can send GET requests to /archive/download with directory traversal sequences to read sensitive system files like /etc/passwd.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11cpe:2.3:a:stvs:provision:5.5:*:*:*:*:*:*:*+ 9 more
- cpe:2.3:a:stvs:provision:5.5:*:*:*:*:*:*:*
- cpe:2.3:a:stvs:provision:5.6:*:*:*:*:*:*:*
- cpe:2.3:a:stvs:provision:5.7:*:*:*:*:*:*:*
- cpe:2.3:a:stvs:provision:5.8.6:*:*:*:*:*:*:*
- cpe:2.3:a:stvs:provision:5.9.0:*:*:*:*:*:*:*
- cpe:2.3:a:stvs:provision:5.9.10:*:*:*:*:*:*:*
- cpe:2.3:a:stvs:provision:5.9.1:*:*:*:*:*:*:*
- cpe:2.3:a:stvs:provision:5.9.7:*:*:*:*:*:*:*
- cpe:2.3:a:stvs:provision:5.9.9:*:*:*:*:*:*:*
- (no CPE)range: =5.9.10
- STVS SA/STVS ProVisionv5Range: 5.9.10 (build 2885-3a8219a)
Patches
Vulnerability mechanics
References
4- www.exploit-db.com/exploits/49481nvdExploitTechnical Description
- www.vulncheck.com/advisories/stvs-provision-authenticated-file-disclosure-via-archiverbnvdThird Party Advisory
- www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5623.phpnvdThird Party Advisory
- www.stvs.chnvdNot Applicable
News mentions
0No linked articles in our index yet.