CVE-2021-43970

HIGH

Quicklert for Digium 10.0.0 (1043) - Authenticated Remote Code Execution via .mp3;.jsp File Upload

Title source: llm
STIX 2.1

Description

An arbitrary file upload vulnerability exists in albumimages.jsp in Quicklert for Digium 10.0.0 (1043) via a .mp3;.jsp filename for a file that begins with audio data bytes. It allows an authenticated (low privileged) attacker to execute remote code on the target server within the context of application's permissions (SYSTEM).

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://quicklert.com

Scores

CVSS v3 8.8
EPSS 0.0175
EPSS Percentile 75.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
quicklert/quicklert 10.0.0
Published Mar 10, 2022
Tracked Since Feb 18, 2026