Security Advisory
CVE-2021-36233
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
The function AdminGetFirstFileContentByFilePath in MIK.starlight 7.9.5.24363 allows (by design) an authenticated attacker to read arbitrary files from the filesystem by specifying the file path.