CVE-2021-44664
HIGHXerte < 3.9 - Path Traversal
Title source: ruleDescription
An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in website_code/php/import/fileupload.php by uploading a maliciously crafted PHP file though the project interface disguised as a language file to bypasses the upload filters. Attackers can manipulate the files destination by abusing path traversal in the 'mediapath' variable.
Exploits (1)
References (4)
Scores
CVSS v3
8.8
EPSS
0.1497
EPSS Percentile
94.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-22
CWE-434
Status
published
Products (1)
xerte/xerte
< 3.9
Published
Feb 24, 2022
Tracked Since
Feb 18, 2026