CVE-2021-47755
Oliver Library Server v5 - Arbitrary File Download
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
Oliver Library Server v5 contains a file download vulnerability that allows unauthenticated attackers to access arbitrary system files through unsanitized input in the FileServlet endpoint. Attackers can exploit the vulnerability by manipulating the 'fileName' parameter to download sensitive files from the server's filesystem.
| CWE | CWE-22 |
| Vendor | softlink education |
| Product | oliver library server |
| Published | Jan 15, 2026 |
| Last Updated | Apr 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for softlink education oliver library server
Be the first to know when new high vulnerabilities affecting softlink education oliver library server are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
Softlink Education / Oliver Library Server
< 8.00.008.053
References
Credits
Mandeep Singh, Ishaan Vij, Luke Blues, CTRL Group