Description
An arbitrary file upload vulnerability was found in Metersphere v1.15.4. Unauthenticated users can upload any file to arbitrary directory, where attackers can write a cron job to execute commands.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://github.com/metersphere/metersphere/issues/8653 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T04:54:29.520Z
Reserved: 2021-12-27T00:00:00.000Z
Link: CVE-2021-45790
No data.
Status : Modified
Published: 2022-09-29T03:15:14.977
Modified: 2024-11-21T06:33:03.277
Link: CVE-2021-45790
No data.
OpenCVE Enrichment
No data.
Weaknesses