Security Advisory
CVE-2021-3317
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
KLog Server through 2.4.1 allows authenticated command injection. async.php calls shell_exec() on the original value of the source parameter.