CVE-2021-44664

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
24/02/2022
Last modified:
12/07/2022

Description

An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in website_code/php/import/fileupload.php by uploading a maliciously crafted PHP file though the project interface disguised as a language file to bypasses the upload filters. Attackers can manipulate the files destination by abusing path traversal in the 'mediapath' variable.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:xerte:xerte:*:*:*:*:*:*:*:* 3.9 (including)