← back
CVE-2021-44664

CVE-2021-44664

28Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 13%
from disclosure to weapon6 days
Published on NVDFeb 24
1st PoC+6d
exploitation probability
13%top 4% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in website_code/php/import/fileupload.php by uploading a maliciously crafted PHP file though the project interface disguised as a language file to bypasses the upload filters. Attackers can manipulate the files destination by abusing path traversal in the 'mediapath' variable.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.