CVE-2021-35062

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
30/08/2021
Last modified:
03/05/2022

Description

A Shell Metacharacter Injection vulnerability in result.php in DRK Odenwaldkreis Testerfassung March-2021 allow an attacker with a valid token of a COVID-19 test result to execute shell commands with the permissions of the web server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:testzentrum-odw:testerfassung:2021-03:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools