CyberRota Analysis
AI analysis pending.
CVE
CVE-2021-26753
Severity
CRITICAL
CVSS
9.9
EPSS
1.15%
Original NVD Description
NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP POST parameter. This allows an attacker to obtain access to the operating system where NeDi is installed and to all application data.