Vulnerability Description
A Remote Command Execution vulnerability on the background in zrlog 2.2.2, at the upload avatar function, could bypass the original limit, upload the JSP file to get a WebShell
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zrlog | Zrlog | 2.2.2 |
Related Weaknesses (CWE)
References
- https://github.com/94fzb/zrlog/issues/115ExploitIssue TrackingThird Party Advisory
- https://github.com/94fzb/zrlog/issues/115ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2021-44093?
CVE-2021-44093 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A Remote Command Execution vulnerability on the background in zrlog 2.2.2, at the upload avatar function, could bypass the original limit, upload the JSP file to get a WebShell
How severe is CVE-2021-44093?
CVE-2021-44093 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-44093?
Check the references section above for vendor advisories and patch information. Affected products include: Zrlog Zrlog.