First published: Thu May 19 2022(Updated: )
Improper input validation vulnerability in HANDY Groupware’s ActiveX moudle allows attackers to download or execute arbitrary files. This vulnerability can be exploited by using the file download or execution path as the parameter value of the vulnerable function.
Credit: vuln@krcert.or.kr
Affected Software | Affected Version | How to fix |
---|---|---|
Handysoft Groupware | <1.7.4.7 | |
Handysoft Groupware | >=2.0.0.0<2.0.3.7 | |
Handysoft Groupware | >=4.0.0.0<4.0.1.8 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26630 is an improper input validation vulnerability in HANDY Groupware’s ActiveX module that allows attackers to download or execute arbitrary files.
Handysoft Groupware versions up to and including 1.7.4.7, 2.0.3.7, and 4.0.1.8 are affected by CVE-2021-26630.
CVE-2021-26630 has a severity rating of 9.8 (Critical).
CVE-2021-26630 can be exploited by using the file download or execution path as the parameter value of the vulnerable function.
You can find more information about CVE-2021-26630 at the following reference link: [https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66723]