Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-44664

An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in website_code/php/import/fileupload.php by uploading a maliciously crafted PHP file though the project interface disguised as a language file to bypasses the upload filters. Attackers can manipulate the files destination by abusing path traversal in the 'mediapath' variable.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.135
EPSS Ranking 93.9%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.5
References
Products affected by CVE-2021-44664
  • Xerte » Xerte » Version: Any
    cpe:2.3:a:xerte:xerte:*


Contact Us

Shodan ® - All rights reserved