CVE-2021-47899 - YetiShare File Hosting Script 5.1.0 Remote File Upload SSRF Vulnerability

CVE-2021-47899 - YetiShare File Hosting Script 5.1.0 Remote File Upload SSRF Vulnerability

CVE ID : CVE-2021-47899 Published : Jan. 23, 2026, 5:16 p.m. | 1 hour, 20 minutes ago Description : YetiShare File Hosting Script 5.1.0 contains a server-side request forgery vulnerability that allows attackers to read local system files through the remote file upload feature. Attackers can exploit the url parameter in the url_upload_handler endpoint to access sensitive files like /etc/passwd by using file:/// protocol. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
Jan. 23, 2026
Attack Vector: local