CVE-2021-41919
08.10.2021, 16:15
webTareas version 2.4 and earlier allows an authenticated user to arbitrarily upload potentially dangerous files without restrictions. This is working by adding or replacing a personal profile picture. The affected endpoint is /includes/upload.php on the HTTP POST data. This allows an attacker to exploit the platform by injecting code or malware and, under certain conditions, to execute code on remote user browsers.Enginsight
| Vendor | Product | Version |
|---|---|---|
| webtareas_project | webtareas | 𝑥 ≤ 2.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration