An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypass, which may be automatically processed within the product's environment or lead to arbitrary code execution.
References
Link | Resource |
---|---|
http://opendocman.com | Product |
https://github.com/opendocman/opendocman | Product Third Party Advisory |
https://github.com/opendocman/opendocman/issues/326 | Issue Tracking Third Party Advisory |
https://github.com/opendocman/opendocman/issues/330 | Exploit Issue Tracking Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2022-03-18T10:55:59
Updated: 2022-03-18T10:55:59
Reserved: 2021-12-27T00:00:00
Link: CVE-2021-45834
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-03-18T11:15:07.917
Modified: 2022-03-25T17:13:46.493
Link: CVE-2021-45834
JSON object: View
Redhat Information
No data.
CWE