PoC Index

CVE-2021-43970

HIGH 9.0EPSS 1.8%

An arbitrary file upload vulnerability exists in albumimages.jsp in Quicklert for Digium 10.0.0 (1043) via a .mp3;.jsp filename for a file that begins with audio data bytes. It allows an authenticated (low privileged) attacker to execute remote code on the target server within the context of application's permissions (SYSTEM).

CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
9.0 HIGHAV:N/AC:L/Au:S/C:C/I:C/A:C
EPSS
1.78% chance of exploitation in the next 30 days, 77th percentile
Published
2022-03-07
Updated
2024-08-04

Proof-of-concept exploits (1)

References

Related