TROYANOSYVIRUS
Back to CVEs

CVE-2021-26634

CRITICAL
9.8

Description

SQL injection and file upload attacks are possible due to insufficient validation of input values in some parameters and variables of files compromising Maxboard, which may lead to arbitrary code execution or privilege escalation. Attackers can use these vulnerabilities to perform attacks such as stealing server management rights using a web shell.

CVE Details

CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published6/2/2022
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0

Affected Products

linux:linux_kernelmaxb:maxboard

Weaknesses (CWE)

CWE-89CWE-288CWE-434CWE-434

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.