Vulnerability Details CVE-2021-26630
Improper input validation vulnerability in HANDY Groupware’s ActiveX moudle allows attackers to download or execute arbitrary files. This vulnerability can be exploited by using the file download or execution path as the parameter value of the vulnerable function.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 58.0%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 7.5
Products affected by CVE-2021-26630
-
cpe:2.3:a:handysoft:groupware:-
-
cpe:2.3:a:handysoft:groupware:1.7.3.1
-
cpe:2.3:a:handysoft:groupware:1.7.4.6
-
cpe:2.3:a:handysoft:groupware:2.0.0.0
-
cpe:2.3:a:handysoft:groupware:2.0.3.6
-
cpe:2.3:a:handysoft:groupware:4.0.0.0
-
cpe:2.3:a:handysoft:groupware:4.0.1.7
-
cpe:2.3:o:microsoft:windows:-