Vulnerability record · CVE-2021-41950 · published 15 November 2021
CVE-2021-41950: ResourceSpace unauthenticated path traversal allows arbitrary file deletion
Montala · Resourcespace
ResourceSpace 9.6 before rev 18277 is vulnerable to directory traversal in pages/ajax/tiles.php via the provider and variant parameters. A remote unauthenticated attacker can delete arbitrary files on the server, including configuration or source code, which can take the application offline for all users.
Description
A directory traversal issue in ResourceSpace 9.6 before 9.6 rev 18277 allows remote unauthenticated attackers to delete arbitrary files on the ResourceSpace server via the provider and variant parameters in pages/ajax/tiles.php. Attackers can delete configuration or source code files, causing the application to become unavailable to all users.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Automated analysis
critical priorityCVSS 9.1 critical with unauthenticated remote file deletion and high EPSS, though not in KEV.
What it is
ResourceSpace 9.6 before rev 18277 is vulnerable to directory traversal in pages/ajax/tiles.php via the provider and variant parameters. A remote unauthenticated attacker can delete arbitrary files on the server, including configuration or source code, which can take the application offline for all users.
Impact
An attacker can delete arbitrary files on the ResourceSpace server, causing loss of configuration or source code and rendering the application unavailable to all users. The CVSS vector shows no confidentiality impact but high integrity and availability impact.
Attack surface
Reachable over the network through HTTP requests to pages/ajax/tiles.php using the provider and variant parameters. No authentication or user interaction is required per the CVSS vector (PR:N, UI:N).
Exploitation
Not listed in CISA KEV, but EPSS is high at 0.749 (99.5th percentile) and a third-party advisory reference is tagged Exploit, indicating public exploit information exists. No ransomware group usage is documented.
What to do
- Upgrade ResourceSpace to 9.6 rev 18277 or later.
- If immediate patching is not possible, restrict or block external access to pages/ajax/tiles.php.
- Validate and sanitize the provider and variant parameters to reject path traversal sequences.
- Run the web application with least privilege and keep backups of configuration and source files to speed recovery.
- Monitor file integrity on the ResourceSpace server to detect unexpected deletions.
Detection
- Review web server logs for requests to pages/ajax/tiles.php with provider or variant parameters containing ../ or encoded traversal sequences.
- Alert on unexpected deletion or modification of ResourceSpace configuration and source files via file integrity monitoring.
- Monitor for application availability failures or errors consistent with missing configuration files.
- Correlate unauthenticated requests to tiles.php with subsequent file system changes on the host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://svn.resourcespace.com/svn/rs/releases/9.6/pages/ajax/tiles.php | Broken LinkVendor Advisory |
| https://www.horizon3.ai/multiple-vulnerabilities-in-resourcespace/ | ExploitThird Party Advisory |
| http://svn.resourcespace.com/svn/rs/releases/9.6/pages/ajax/tiles.php | Broken LinkVendor Advisory |
| https://www.horizon3.ai/multiple-vulnerabilities-in-resourcespace/ | ExploitThird Party Advisory |
Track CVE-2021-41950 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-41950), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.