CVE-2021-21055

CWE-4263 documents3 sources
Severity
6.2MEDIUM
EPSS
0.5%
top 34.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 11
Latest updateMay 24

Description

Adobe Dreamweaver versions 21.0 (and earlier) and 20.2 (and earlier) is affected by an untrusted search path vulnerability that could result in information disclosure. An attacker with physical access to the system could replace certain configuration files and dynamic libraries that Dreamweaver references, potentially resulting in information disclosure.

CVSS vector

CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:HExploitability: 0.3 | Impact: 5.9

Affected Packages2 packages

CVEListV5adobe/dreamweaverunspecified21.0+2
NVDadobe/dreamweaver20.2+1

🔴Vulnerability Details

2
GHSA
GHSA-x4c3-xfxx-vh9f: Adobe Dreamweaver versions 212022-05-24
CVEList
Adobe Dreamweaver Untrusted Search Path Vulnerability Could Lead To Information Disclosure2021-02-11
CVE-2021-21055 (MEDIUM CVSS 6.2) | Adobe Dreamweaver versions 21.0 (an | cvebase.io