CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.5. It may be remotely exploitable.
CVE
CVE-2021-26804
Severity
MEDIUM
CVSS
6.5
EPSS
1.19%
Original NVD Description
Insecure Permissions in Centreon Web versions 19.10.18, 20.04.8, and 20.10.2 allows remote attackers to bypass validation by changing any file extension to ".gif", then uploading it in the "Administration/ Parameters/ Images" section of the application.
Related CVEs
Other vulnerabilities affecting the same vendor(s)