PT-2021-20057 · Unknown · Klog Server

Published

2021-01-26

·

Updated

2021-02-01

·

CVE-2021-3317

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions KLog Server versions 2.4.1 and earlier
Description The issue allows authenticated command injection. This is because async.php calls shell exec() on the original value of the source parameter.
Recommendations For versions 2.4.1 and earlier, consider disabling the shell exec() function call in async.php until a patch is available. Restrict access to async.php to minimize the risk of exploitation. Avoid using the source parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-3317

Affected Products

Klog Server