Vulnerability Description
An arbitrary file upload vulnerability exists in albumimages.jsp in Quicklert for Digium 10.0.0 (1043) via a .mp3;.jsp filename for a file that begins with audio data bytes. It allows an authenticated (low privileged) attacker to execute remote code on the target server within the context of application's permissions (SYSTEM).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Quicklert | Quicklert | 10.0.0 |
Related Weaknesses (CWE)
References
- https://quicklert.comVendor Advisory
- https://www.assurainc.com/assura-announces-discovery-of-two-vulnerabilities-in-qExploitThird Party Advisory
- https://quicklert.comVendor Advisory
- https://www.assurainc.com/assura-announces-discovery-of-two-vulnerabilities-in-qExploitThird Party Advisory
FAQ
What is CVE-2021-43970?
CVE-2021-43970 is a vulnerability with a CVSS score of 8.8 (HIGH). An arbitrary file upload vulnerability exists in albumimages.jsp in Quicklert for Digium 10.0.0 (1043) via a .mp3;.jsp filename for a file that begins with audio data bytes. It allows an authenticated...
How severe is CVE-2021-43970?
CVE-2021-43970 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-43970?
Check the references section above for vendor advisories and patch information. Affected products include: Quicklert Quicklert.