Vulnerability Description
An issue was discovered in Opmantek Open-AudIT after 3.5.0. Without authentication, a vulnerability in code_igniter/application/controllers/util.php allows an attacker perform command execution without echoes.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opmantek | Open-Audit | >= 3.5.0, < 4.3.0 |
References
- https://community.opmantek.com/pages/viewpage.action?pageId=65504438PatchVendor Advisory
- https://github.com/Opmantek/open-audit/commit/c7595cbb092e410a487f03c0eb536cf19ePatchThird Party Advisory
- https://community.opmantek.com/pages/viewpage.action?pageId=65504438PatchVendor Advisory
- https://github.com/Opmantek/open-audit/commit/c7595cbb092e410a487f03c0eb536cf19ePatchThird Party Advisory
FAQ
What is CVE-2021-40612?
CVE-2021-40612 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered in Opmantek Open-AudIT after 3.5.0. Without authentication, a vulnerability in code_igniter/application/controllers/util.php allows an attacker perform command execution withou...
How severe is CVE-2021-40612?
CVE-2021-40612 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-40612?
Check the references section above for vendor advisories and patch information. Affected products include: Opmantek Open-Audit.