CVE-2021-41646: Malicious File Upload
Published Oct 29, 2021
·Updated
Remote Code Execution (RCE) vulnerability exists in Sourcecodester Online Reviewer System 1.0 by uploading a maliciously crafted PHP file that bypasses the image upload filters..
Affected Software
2 affected components
Online Reviewer System Project Online Reviewer System=1.0
Janobe Online Reviewer System=1.0
Event History
Oct 29, 2021
CVE Published
via MITRE·05:02 PM
Data Sourced
via MITRE·05:02 PM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-41646?
CVE-2021-41646 is classified as a Remote Code Execution (RCE) vulnerability.
2
How do I fix CVE-2021-41646?
To fix CVE-2021-41646, ensure that file upload filters are properly configured to reject malicious PHP files.
3
What can an attacker do with CVE-2021-41646?
An attacker can exploit CVE-2021-41646 to upload a malicious PHP file and execute arbitrary code on the server.
4
Which software versions are affected by CVE-2021-41646?
CVE-2021-41646 affects version 1.0 of the Sourcecodester Online Reviewer System.
5
Is CVE-2021-41646 being actively exploited?
There have been reports of CVE-2021-41646 being exploited in the wild due to its nature of allowing remote code execution.