Fiche vulnérabilité
CVE-2021-26612 : faille critique tobesoft nexacro (CVSS 9.8)
Description
An improper input validation leading to arbitrary file creation was discovered in copy method of Nexacro platform. Remote attackers use copy method to execute arbitrary command after the file creation included malicious code.
En bref
- Sévérité
- Critique (CVSS 9.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 30 nov. 2021
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- tobesoft nexacro