CVE-2021-26630: HANDY Groupware file download and execute vulnerability
Improper input validation vulnerability in HANDY Groupware’s ActiveX moudle allows attackers to download or execute arbitrary files. This vulnerability can be exploited by using the file download or execution path as the parameter value of the vulnerable function.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-26630?
CVE-2021-26630 is an improper input validation vulnerability in HANDY Groupware’s ActiveX module that allows attackers to download or execute arbitrary files.
What software is affected by CVE-2021-26630?
Handysoft Groupware versions up to and including 1.7.4.7, 2.0.3.7, and 4.0.1.8 are affected by CVE-2021-26630.
How severe is CVE-2021-26630?
CVE-2021-26630 has a severity rating of 9.8 (Critical).
How can CVE-2021-26630 be exploited?
CVE-2021-26630 can be exploited by using the file download or execution path as the parameter value of the vulnerable function.
Where can I find more information about CVE-2021-26630?
You can find more information about CVE-2021-26630 at the following reference link: [https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66723]