CVE-2021-44664
HIGHXerte < 3.9 - Authenticated Remote Code Execution via Language File Upload
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-44664. PoCs published by Rik Lutz.
AI-analyzed exploit summary This exploit leverages an authenticated file upload vulnerability in Xerte to overwrite a language file with a PHP web shell, enabling remote code execution. It automates the process of creating a project, extracting the installation path, and uploading malicious content.
Description
An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in website_code/php/import/fileupload.php by uploading a maliciously crafted PHP file though the project interface disguised as a language file to bypasses the upload filters. Attackers can manipulate the files destination by abusing path traversal in the 'mediapath' variable.
Exploits (1)
This exploit leverages an authenticated file upload vulnerability in Xerte to overwrite a language file with a PHP web shell, enabling remote code execution. It automates the process of creating a project, extracting the installation path, and uploading malicious content.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H