10
CVSSv2

CVE-2021-41560

Published: 15/12/2021 Updated: 17/12/2021
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

OpenCATS up to and including 0.9.6 allows remote malicious users to execute arbitrary code by uploading an executable file via lib/FileUtility.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

opencats opencats

Github Repositories

OpenCATS <= 0.9.4 RCE (CVE-2021-41560)

RevCAT OpenCATS &lt;= 094 RCE (CVE-2021-41560) Opencats &lt;= 094 fails to properly validade file upload, leading to remote code execution If your installed version is &lt;= 094, apply the patch asap Usage /RevCATsh &lt;target URL&gt; Note: &lt;target URL&gt; must point to the root path where OpenCAT