peter bassill · operator
$ cve CVE-2021-44159 JSON

CVE-2021-44159

9.8
CRITICAL · CVSS 3.1 · EPSS 3.4% (pctl 89)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

4MOSAn GCB Doctor’s file upload function has improper user privilege control. A remote attacker can upload arbitrary files including webshell files without authentication and execute arbitrary code in order to perform arbitrary system operations or deny of service attack.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.41% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-434
On CISA KEVno
Public exploitnone known
Published2021-12-20
Last modified2026-06-17

Affected (1)

VendorProduct
4mosangcb doctor

References

→ the Explorer  ·  watch your stack  ·  NVD