HIGH🇵🇱 Wersja polska

CVE-2021-26752

CVSS 8.8v3.1pub. 2021-02-12upd. 2024-11-21

NeDi 1.9C allows an authenticated user to execute operating system commands in the Nodes Traffic function on the endpoint /Nodes-Traffic.php via the md or ag HTTP GET parameter. This allows an attacker to obtain access to the operating system where NeDi is installed and to all application data.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Nedi

    APP
    Nedi
    1.9c
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2022-40895CRITICAL9.1PL ✓same product

NeDi — User Enumeration w formularzu logowania i resetowania hasła

CVE-2021-26753CRITICAL9.9PL ✓same product

NeDi 1.9C — wstrzyknięcie kodu PHP przez uwierzytelnionego użytkownika

CVE-2021-26751HIGH8.8same product

NeDi 1.9C allows an authenticated user to perform a SQL Injection in the Monitoring History function on the en...

CVE-2020-14414HIGH8.8same product

NeDi 1.9C is vulnerable to Remote Command Execution. pwsec.php improperly escapes shell metacharacters from a ...

CVE-2020-14412HIGH8.8same product

NeDi 1.9C is vulnerable to Remote Command Execution. System-Snapshot.php improperly escapes shell metacharacte...