Security Advisory

CVE-2021-44664

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-02-24 20:11:21
Last updated 2024-08-04 04:25:16
Assigner mitre
State PUBLISHED

Description

An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in website_code/php/import/fileupload.php by uploading a maliciously crafted PHP file though the project interface disguised as a language file to bypasses the upload filters. Attackers can manipulate the files destination by abusing path traversal in the mediapath variable.