CRITICAL

CVE-2021-45790

CVSS v3

9.8

CRITICAL

EPSS Score

32.4%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

An arbitrary file upload vulnerability was found in Metersphere v1.15.4. Unauthenticated users can upload any file to arbitrary directory, where attackers can write a cron job to execute commands.

Technical details

Published
9/29/2022

Frequently asked questions

What is CVE-2021-45790?

An arbitrary file upload vulnerability was found in Metersphere v1.15.4. Unauthenticated users can upload any file to arbitrary directory, where attackers can write a cron job to execute commands.

Is CVE-2021-45790 actively exploited?

Active exploitation of CVE-2021-45790 has not been confirmed. The EPSS score is 32.4%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-45790?

CVE-2021-45790 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2021-45790 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.