{"id":"CVE-2021-47899","title":"YetiShare File Hosting Script 5.1.0 Remote File Upload SSRF Vulnerability","summary":"YetiShare File Hosting Script 5.1.0 contains a server-side request forgery vulnerability that allows attackers to read local system files through the remote file upload feature. Attackers can exploit the url parameter in the url_upload_h…","severity":"medium","cvss":4,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","cvssSource":"cna","cwe":["CWE-434"],"vendor":"Mfscripts","product":"YetiShare File Hosting Script","affected":["yetishare_file_hosting_script v5.1.0"],"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"partial","timestamp":"2026-01-23T20:55:38.276190Z"},"exploitAvailable":true,"published":"2026-01-23","updated":"2026-10-01","sourceUpdated":"2026-10-01T21:44:53.452Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2021-47899","references":[{"url":"https://www.exploit-db.com/exploits/49534","label":"ExploitDB-49534"},{"url":"https://mfscripts.com","label":"Vendor Homepage"},{"url":"https://yetishare.com","label":"Software Product Page"},{"url":"https://www.vulncheck.com/advisories/yetishare-file-hosting-script-remote-file-upload-ssrf-vulnerability","label":"VulnCheck Advisory: YetiShare File Hosting Script 5.1.0 Remote File Upload SSRF Vulnerability"}],"tags":["cve.org","exploit-available"],"epss":0.00294,"epssPercentile":0.19847,"ingestedAt":"2026-10-01T23:03:32.844Z","slug":"CVE-2021-47899","body":"## Overview\n\nYetiShare File Hosting Script 5.1.0 contains a server-side request forgery vulnerability that allows attackers to read local system files through the remote file upload feature. Attackers can exploit the url parameter in the url_upload_handler endpoint to access sensitive files like /etc/passwd by using file:/// protocol.\n\n## Affected\n\n- `yetishare_file_hosting_script v5.1.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":34,"depthScoreParts":{"impact":22,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}