7.5
CVSSv2

CVE-2021-26473

Published: 08/06/2021 Updated: 22/04/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

In VembuBDR prior to 4.2.0.1 and VembuOffsiteDR prior to 4.2.0.1 the http API located at /sgwebservice_o.php action logFilePath allows an malicious user to write arbitrary files in the context of the web server process. These files can then be executed remotely by calling the file via the web server.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vembu bdr suite

vembu offsite dr