NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP POST parameter. This allows an attacker to obtain access to the operating system where NeDi is installed and to all application data.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2021-02-12T20:35:20
Updated: 2024-08-03T20:33:40.925Z
Reserved: 2021-02-05T00:00:00
Link: CVE-2021-26753
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-02-12T21:15:13.027
Modified: 2024-11-21T05:56:48.080
Link: CVE-2021-26753
Redhat
No data.