← Vulnerability feed

Vulnerability record · CVE-2021-41950 · published 15 November 2021

CVE-2021-41950: ResourceSpace unauthenticated path traversal allows arbitrary file deletion

Montala · Resourcespace

ResourceSpace 9.6 before rev 18277 is vulnerable to directory traversal in pages/ajax/tiles.php via the provider and variant parameters. A remote unauthenticated attacker can delete arbitrary files on the server, including configuration or source code, which can take the application offline for all users.

9.1 CVSS 3.1 Critical EPSS 75% · top 0.5% CWE-22 · Path traversal
9.1CVSS 3.1 base score, v2 6.4
75%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A directory traversal issue in ResourceSpace 9.6 before 9.6 rev 18277 allows remote unauthenticated attackers to delete arbitrary files on the ResourceSpace server via the provider and variant parameters in pages/ajax/tiles.php. Attackers can delete configuration or source code files, causing the application to become unavailable to all users.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.1 critical with unauthenticated remote file deletion and high EPSS, though not in KEV.

What it is

ResourceSpace 9.6 before rev 18277 is vulnerable to directory traversal in pages/ajax/tiles.php via the provider and variant parameters. A remote unauthenticated attacker can delete arbitrary files on the server, including configuration or source code, which can take the application offline for all users.

Impact

An attacker can delete arbitrary files on the ResourceSpace server, causing loss of configuration or source code and rendering the application unavailable to all users. The CVSS vector shows no confidentiality impact but high integrity and availability impact.

Attack surface

Reachable over the network through HTTP requests to pages/ajax/tiles.php using the provider and variant parameters. No authentication or user interaction is required per the CVSS vector (PR:N, UI:N).

Exploitation

Not listed in CISA KEV, but EPSS is high at 0.749 (99.5th percentile) and a third-party advisory reference is tagged Exploit, indicating public exploit information exists. No ransomware group usage is documented.

What to do

  • Upgrade ResourceSpace to 9.6 rev 18277 or later.
  • If immediate patching is not possible, restrict or block external access to pages/ajax/tiles.php.
  • Validate and sanitize the provider and variant parameters to reject path traversal sequences.
  • Run the web application with least privilege and keep backups of configuration and source files to speed recovery.
  • Monitor file integrity on the ResourceSpace server to detect unexpected deletions.

Detection

  • Review web server logs for requests to pages/ajax/tiles.php with provider or variant parameters containing ../ or encoded traversal sequences.
  • Alert on unexpected deletion or modification of ResourceSpace configuration and source files via file integrity monitoring.
  • Monitor for application availability failures or errors consistent with missing configuration files.
  • Correlate unauthenticated requests to tiles.php with subsequent file system changes on the host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-41950 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-41765ResourceSpace unauthenticated SQL injection in add_keyword.phpResourceSpace 9.5 and 9.6 before rev 18274 contains a SQL injection flaw in pages/edit_fields/9_ajax/add_keyword.php reachable through the k paramete…EPSS 68%analysed8.8CVE-2019-25662Montala resourcespace sql injection vulnerabilityResourceSpace 8.6 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicio…EPSS 0.42%7.5CVE-2015-6915Montala resourcespace sql injection vulnerabilitySQL injection vulnerability in Montala Limited ResourceSpace 7.3.7009 and earlier allows remote attackers to execute arbitrary SQL commands via the "…EPSS 1.8%7.5CVE-2015-3648Montala resourcespace path traversal vulnerabilityDirectory traversal vulnerability in pages/setup.php in Montala Limited ResourceSpace before 7.2.6727 allows remote attackers to include and execute …EPSS 8.0%7.1CVE-2019-25693Montala resourcespace cross-site request forgery vulnerabilityResourceSpace 8.6 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious…EPSS 0.16%6.5CVE-2022-31260Montala resourcespace missing authentication for critical function vulnerabilityIn Montala ResourceSpace through 9.8 before r19636, csv_export_results_metadata.php allows attackers to export collection metadata via a non-NULL k v…EPSS 2.0%6.1CVE-2021-41951ResourceSpace reflected XSS in WordPress SSO pluginResourceSpace before 9.6 rev 18290 contains a reflected cross-site scripting flaw in plugins/wordpress_sso/pages/index.php, reachable through the wor…EPSS 78%analysed5.0CVE-2011-4311Montala resourcespace improper input validation vulnerabilityResourceSpace before 4.2.2833 does not properly validate access keys, which allows remote attackers to bypass intended resource restrictions via unsp…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2021-41950), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.