PT-2021-7749 · Filezen · Filezen
Published
2021-02-16
·
Updated
2021-02-22
·
CVE-2021-20655
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
FileZen versions 3.0.0 through 4.2.7
FileZen versions 5.0.0 through 5.0.2
Description
The issue is related to the web administration interface of the FileZen file sharing server, which fails to neutralize special elements used in operating system commands. This allows a remote attacker with administrator rights to execute arbitrary OS commands.
Recommendations
For versions 3.0.0 through 4.2.7, update to a version outside of this range to mitigate the risk.
For versions 5.0.0 through 5.0.2, update to a version outside of this range to mitigate the risk.
As a temporary workaround, consider restricting access to the administration interface to minimize the risk of exploitation.
Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Filezen