CVE-2021-27513
high · 8.8The module admin_ITSM in EyesOfNetwork 5.3-10 allows remote authenticated users to upload arbitrary .xml.php files because it relies on "le filtre userside."
8.8
CVSS
28.4%
EPSS (exploit prob.)
98th
EPSS percentile
2021-02-22
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-434
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| eyesofnetwork | eyesofnetwork | 5.3-10 |
Check a specific version with /api/v1/cve/match.
References
- https://github.com/ArianeBlow/exploit-eyesofnetwork5.3.10/blob/main/PoC-BruteForceID-arbitraty-file-upload-RCE-PrivEsc.py
- https://github.com/EyesOfNetworkCommunity/eonweb/issues/87
- https://github.com/ArianeBlow/exploit-eyesofnetwork5.3.10/blob/main/PoC-BruteForceID-arbitraty-file-upload-RCE-PrivEsc.py
- https://github.com/EyesOfNetworkCommunity/eonweb/issues/87
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-27513