CVE-2021-26752
12.02.2021, 21:15
NeDi 1.9C allows an authenticated user to execute operating system commands in the Nodes Traffic function on the endpoint /Nodes-Traffic.php via the md or ag HTTP GET parameter. This allows an attacker to obtain access to the operating system where NeDi is installed and to all application data.
Vendor | Product | Version |
---|---|---|
nedi | nedi | 1.9c:c |
𝑥
= Vulnerable software versions