Skip to main content
HIGH

CVE-2021-43970

CVSS v3

8.8

HIGH

EPSS Score

1.8 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

An arbitrary file upload vulnerability exists in albumimages.jsp in Quicklert for Digium 10.0.0 (1043) via a .mp3;.jsp filename for a file that begins with audio data bytes. It allows an authenticated (low privileged) attacker to execute remote code on the target server within the context of application's permissions (SYSTEM).

Technical details

Published
2022-03-10

Frequently asked questions

What is CVE-2021-43970?

An arbitrary file upload vulnerability exists in albumimages.jsp in Quicklert for Digium 10.0.0 (1043) via a .mp3;.jsp filename for a file that begins with audio data bytes. It allows an authenticated (low privileged) attacker to execute remote code on the target server within the context of application's permissions (SYSTEM).

Is CVE-2021-43970 actively exploited?

Active exploitation of CVE-2021-43970 has not been confirmed. Its EPSS score was 1.8% on 2026-09-25, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-43970?

CVE-2021-43970 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2021-43970 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key