← back
CVE-2021-35244medium

Unrestricted File Upload Causing Remote Code Execution: Orion Platform 2020.2.6

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.8epss 5.8%
exploitation probability
5.8%top 7% of all CVEs
observed exploitation
nono source reports it
The "Log alert to a file" action within action management enables any Orion Platform user with Orion alert management rights to write to any file. An attacker with Orion alert management rights could use this vulnerability to perform an unrestricted file upload causing a remote code execution.
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L