CVE-2021-29281: Malicious File Upload
Published Jul 7, 2022
·Updated
File upload vulnerability in GFI Mail Archiver versions up to and including 15.1 via insecure implementation of Telerik Web UI plugin which is affected by CVE-2014-2217, and CVE-2017-11317.
Affected Software
1 affected component
GFI Archiver<15.2
Event History
Jul 7, 2022
CVE Published
via MITRE·07:38 PM
Data Sourced
via MITRE·07:38 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-29281?
CVE-2021-29281 is considered a critical vulnerability due to the potential for unauthorized file uploads.
2
How do I fix CVE-2021-29281?
To fix CVE-2021-29281, upgrade GFI Mail Archiver to version 15.2 or later, which addresses the vulnerability.
3
What systems are affected by CVE-2021-29281?
CVE-2021-29281 affects GFI Mail Archiver versions up to and including 15.1.
4
What type of vulnerability is CVE-2021-29281?
CVE-2021-29281 is classified as a file upload vulnerability resulting from an insecure implementation in the Telerik Web UI plugin.
5
Can CVE-2021-29281 lead to data breaches?
Yes, exploiting CVE-2021-29281 can result in unauthorized access to the server, potentially leading to data breaches.