Elcomplus SmartPPT是美国Elcomplus公司的一个集成语音和数据调度软件。 Elcomplus SmartPPT存在路径遍历漏洞,该漏洞源于该软件使用外部输入来构造一个路径名,该路径名应位于受限目录中,但它无法正确转义特殊字符序列,该序列可以解析到该目录之外的位置。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-43934 | 9.8 CRITICAL | Elcomplus SmartPtt Unrestricted Upload of File with Dangerous Type |
| CVE-2021-43932 | 9.0 CRITICAL | Elcomplus SmartPtt Cross-site Scripting |
| CVE-2021-43939 | 8.8 HIGH | Elcomplus SmartPtt Improper Authorization |
No comments yet