CVE-2021-47755 - CVE House
Back to Database
Status published High CVE-2021-47755

Oliver Library Server v5 - Arbitrary File Download

Vulnerability Description

Oliver Library Server v5 contains a file download vulnerability that allows unauthenticated attackers to access arbitrary system files through unsanitized input in the FileServlet endpoint. Attackers can exploit the vulnerability by manipulating the 'fileName' parameter to download sensitive files from the server's filesystem.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-47755

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Mandeep Singh, Ishaan Vij, Luke Blues, CTRL Group

Affected Vendor

Softlink Education

View all reports →

Affected Software

Oliver Library Server
Vulnerable Versions:
< 8.00.008.053

Timeline

Official Publish: January 15th, 2026
Last Modified: April 7th, 2026
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)