CVE-2021-43970

HIGH

Quicklert for Digium 10.0.0 - RCE

Title source: llm
STIX 2.1

Description

An arbitrary file upload vulnerability exists in albumimages.jsp in Quicklert for Digium 10.0.0 (1043) via a .mp3;.jsp filename for a file that begins with audio data bytes. It allows an authenticated (low privileged) attacker to execute remote code on the target server within the context of application's permissions (SYSTEM).

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://quicklert.com

Scores

CVSS v3 8.8
EPSS 0.0070
EPSS Percentile 72.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
quicklert/quicklert 10.0.0
Published Mar 10, 2022
Tracked Since Feb 18, 2026