NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP POST parameter. This allows an attacker to obtain access to the operating system where NeDi is installed and to all application data.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2021-02-12T20:35:20
Updated: 2024-08-03T20:33:40.925Z
Reserved: 2021-02-05T00:00:00
Link: CVE-2021-26753

No data.

Status : Modified
Published: 2021-02-12T21:15:13.027
Modified: 2024-11-21T05:56:48.080
Link: CVE-2021-26753

No data.