CVE-2021-36122
HIGHEcho ShareCare 8.15.5 - Command Injection
Title source: llmDescription
An issue was discovered in Echo ShareCare 8.15.5. The UnzipFile feature in Access/EligFeedParse_Sup/UnzipFile_Upd.cfm is susceptible to a command argument injection vulnerability when processing remote input in the zippass parameter from an authenticated user, leading to the ability to inject arbitrary arguments to 7z.exe.
Scores
CVSS v3
8.8
EPSS
0.0094
EPSS Percentile
76.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-88
Status
published
Affected Products (1)
echobh/sharecare
Timeline
Published
Jul 13, 2021
Tracked Since
Feb 18, 2026