CVE-2021-30461
29.05.2021, 14:15
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used, the user-supplied SPOOLDIR value (which might contain PHP code) is injected into config/configuration.php.
Vendor | Product | Version |
---|---|---|
voipmonitor | voipmonitor | 𝑥 < 24.61 |
𝑥
= Vulnerable software versions