PT-2022-9779 · Unknown · Handy Groupware

Published

2022-05-19

·

Updated

2022-06-01

·

CVE-2021-26630

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HANDY Groupware (affected versions not specified)
Description The issue is related to an improper input validation vulnerability in HANDY Groupware's ActiveX module. This allows attackers to download or execute arbitrary files by exploiting the file download or execution path as the parameter value of the vulnerable function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-26630

Affected Products

Handy Groupware