← volver
CVE-2021-35243

HTTP PUT & DELETE Methods Enabled

CVSS 5.3 MEDIUMEPSS 0.9%CWE-749
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.3EPSS 0.9%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
23 dic 2021Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
The HTTP PUT and DELETE methods were enabled in the Web Help Desk web server (12.7.7 and earlier), allowing users to execute dangerous HTTP requests. The HTTP PUT method is normally used to upload data that is saved on the server with a user-supplied URL. While the DELETE method requests that the origin server removes the association between the target resource and its current functionality. Improper use of these methods may lead to a loss of integrity.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Productos afectados
SolarWinds · Web Help Desk

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →