← Back

CVE-2021-26630

nvd nist
Published: May 19, 2022Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Improper input validation vulnerability in HANDY Groupware’s ActiveX moudle allows attackers to download or execute arbitrary files. This vulnerability can be exploited by using the file download or execution path as the parameter value of the vulnerable function.

Affected (3)

Products: Handysoft: Groupware
1 product
Groupware
Configuration A
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Handysoft
Before 1.7.4.7
From 2.0.0.0 to 2.0.3.7
From 4.0.0.0 to 4.0.1.8
Running on/withPlatform Versions
Microsoft
Windows
All versions

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.