Vulnerability Description
In MartDevelopers KEA-Hotel-ERP open source as of 12-31-2021, a remote code execution vulnerability can be exploited by uploading PHP files using the file upload vulnerability in this service.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kea-Hotel-Erp Project | Kea-Hotel-Erp | - |
Related Weaknesses (CWE)
References
- https://blog.pocas.kr/posts/rce-KEA-Hotel-ERP/Broken Link
- https://gist.github.com/P0cas/5aa55f62781364a750ac4a4d47f319fa#cve-2021-46113ExploitThird Party Advisory
- https://www.youtube.com/watch?v=gnSMrvV5e9wExploitThird Party Advisory
- https://blog.pocas.kr/posts/rce-KEA-Hotel-ERP/Broken Link
- https://gist.github.com/P0cas/5aa55f62781364a750ac4a4d47f319fa#cve-2021-46113ExploitThird Party Advisory
- https://www.youtube.com/watch?v=gnSMrvV5e9wExploitThird Party Advisory
FAQ
What is CVE-2021-46113?
CVE-2021-46113 is a vulnerability with a CVSS score of 8.8 (HIGH). In MartDevelopers KEA-Hotel-ERP open source as of 12-31-2021, a remote code execution vulnerability can be exploited by uploading PHP files using the file upload vulnerability in this service.
How severe is CVE-2021-46113?
CVE-2021-46113 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-46113?
Check the references section above for vendor advisories and patch information. Affected products include: Kea-Hotel-Erp Project Kea-Hotel-Erp.