First published: Thu Apr 28 2022(Updated: )
novel-plus V3.6.1 allows unrestricted file uploads. Unrestricted file suffixes and contents can lead to server attacks and arbitrary code execution.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xxyopen Novel-plus | =3.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-41921 is critical with a score of 9.8.
CVE-2021-41921 refers to a vulnerability in novel-plus V3.6.1 that allows unrestricted file uploads, which can lead to server attacks and arbitrary code execution.
novel-plus V3.6.1 is affected by CVE-2021-41921.
Unrestricted file uploads in novel-plus V3.6.1 can be exploited by uploading files with malicious suffixes and contents, leading to server attacks and potential arbitrary code execution.
Yes, you can find more information about CVE-2021-41921 at the following link: [GitHub Issue #62](https://github.com/201206030/novel-plus/issues/62).