CVE Database · CVE-2021-35244
CVSS v3.1
6.8
EPSS
5.77%
Published
Dec 20, 2021
Modified
Nov 21, 2024
Public PoC / Exploit
All weaponized →No public PoC or exploit code indexed for this CVE.
Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
The "Log alert to a file" action within action management enables any Orion Platform user with Orion alert management rights to write to any file. An attacker with Orion alert management rights could use this vulnerability to perform an unrestricted file upload causing a remote code execution.
CVSS Vector
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:LWeaknesses (CWE)
Affected Products (5)
References (8)