E21-c6be1
CVSS:
9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
False Positive:
f
Variants:
2
Year:
2021
Description
This strike exploits a file upload vulnerability in VMware View Planner.
An remote unauthenticated attacker can send a malicious HTTP POST request to upload an arbitrary file via 'logupload' endpoint. Successful exploitation can lead to execution of arbitrary code on the target system with root privileges.
CVE
References
https://github.com/GreyOrder/CVE-2021-21978