Логотип exploitDog
bind:CVE-2021-44967
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-44967

Количество 3

Количество 3

nvd логотип

CVE-2021-44967

почти 4 года назад

A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file. NOTE: the Supplier's position is that plugins intentionally can contain arbitrary PHP code, and can only be installed by a superadmin, and therefore the security model is not violated by this finding.

CVSS3: 8.8
EPSS: Средний
debian логотип

CVE-2021-44967

почти 4 года назад

A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 ...

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-58c2-r57v-99r7

почти 4 года назад

A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file.

CVSS3: 8.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-44967

A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file. NOTE: the Supplier's position is that plugins intentionally can contain arbitrary PHP code, and can only be installed by a superadmin, and therefore the security model is not violated by this finding.

CVSS3: 8.8
68%
Средний
почти 4 года назад
debian логотип
CVE-2021-44967

A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 ...

CVSS3: 8.8
68%
Средний
почти 4 года назад
github логотип
GHSA-58c2-r57v-99r7

A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file.

CVSS3: 8.8
68%
Средний
почти 4 года назад

Уязвимостей на страницу