ZeroHour

CVE-2021-44159

CVSS 3.1
9.8 critical
EPSS
3%p88
Published
()
Modified
Description

4MOSAn GCB Doctor’s file upload function has improper user privilege control. A remote attacker can upload arbitrary files including webshell files without authentication and execute arbitrary code in order to perform arbitrary system operations or deny of service attack.

Vendors
4mosan
Products
gcb doctor
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.