← Back to browse · API

CVE-2021-44159

Severity
CRITICAL
CVSS
9.8
EPSS
0.03409
Risk score
40.39
CISA KEV
No
PoC
No
Published
2021-12-20
Modified
2024-09-17
First seen
2026-08-07
Aliases
EUVD-2021-31009, GHSA-2PG3-5VWJ-WH4M
Products
4MOSAn:GCB Doctor unspecified ≤20210811(2.0)
Sources
euvd EUVD-2021-31009

Description

4MOSAn GCB Doctor’s file upload function has improper user privilege control. A remote attacker can upload arbitrary files including webshell files without authentication and execute arbitrary code in order to perform arbitrary system operations or deny of service attack.

References