Security Advisory

CVE-2021-42675

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-06-14 16:29:42
Last updated 2024-08-04 03:38:50
Assigner mitre
State PUBLISHED

Description

Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory. One can upload a malicious PHP file and obtain remote code execution.