Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-31769

Опубликовано: 21 июн. 2021
Источник: nvd
CVSS3: 8.8
CVSS2: 9
EPSS Низкий

Описание

MyQ Server in MyQ X Smart before 8.2 allows remote code execution by unprivileged users because administrative session data can be read in the %PROGRAMFILES%\MyQ\PHP\Sessions directory. The "Select server file" feature is only intended for administrators but actually does not require authorization. An attacker can inject arbitrary OS commands (such as commands to create new .php files) via the Task Scheduler component.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:myq-solution:myq_server:*:*:*:*:*:*:*:*
Версия до 8.2 (исключая)

EPSS

Процентиль: 90%
0.05068
Низкий

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-78

Связанные уязвимости

github
больше 3 лет назад

MyQ Server in MyQ X Smart before 8.2 allows remote code execution by unprivileged users because administrative session data can be read in the %PROGRAMFILES%\MyQ\PHP\Sessions directory. The "Select server file" feature is only intended for administrators but actually does not require authorization. An attacker can inject arbitrary OS commands (such as commands to create new .php files) via the Task Scheduler component.

EPSS

Процентиль: 90%
0.05068
Низкий

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-78