CVE-2021-3317

Publication date

2021-01-26 22:33:58

Family

mitre

State

PUBLISHED

Description

KLog Server through 2.4.1 allows authenticated command injection. async.php calls shell_exec() on the original value of the source parameter.