CVE-2021-26753
12.02.2021, 21:15
NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP POST parameter. This allows an attacker to obtain access to the operating system where NeDi is installed and to all application data.Enginsight
Vendor | Product | Version |
---|---|---|
nedi | nedi | 1.9c:c |
𝑥
= Vulnerable software versions