Lucene search

K
cvelistMitreCVELIST:CVE-2021-26753
HistoryFeb 12, 2021 - 8:35 p.m.

CVE-2021-26753

2021-02-1220:35:20
mitre
www.cve.org
4
nedi
php code injection
system files
operating system
application data

AI Score

9.5

Confidence

High

EPSS

0.001

Percentile

44.1%

NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP POST parameter. This allows an attacker to obtain access to the operating system where NeDi is installed and to all application data.

AI Score

9.5

Confidence

High

EPSS

0.001

Percentile

44.1%

Related for CVELIST:CVE-2021-26753