CVE-2021-44664: Path Traversal
An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in websitecode/php/import/fileupload.php by uploading a maliciously crafted PHP file though the project interface disguised as a language file to bypasses the upload filters. Attackers can manipulate the files destination by abusing path traversal in the 'mediapath' variable.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-44664?
The severity of CVE-2021-44664 is classified as critical due to its ability to allow authenticated remote code execution.
How do I fix CVE-2021-44664?
To fix CVE-2021-44664, users should update Xerte to a version later than 3.9 that addresses this vulnerability.
What potential impacts could CVE-2021-44664 have on my system?
CVE-2021-44664 could allow attackers to execute arbitrary PHP code, potentially compromising the entire system.
Who is affected by CVE-2021-44664?
CVE-2021-44664 affects all versions of Xerte up to and including version 3.9.
Is user authentication required to exploit CVE-2021-44664?
Yes, exploitation of CVE-2021-44664 requires authenticated access to the Xerte platform.