The "Log alert to a file" action within action management enables any Orion Platform user with Orion alert management rights to write to any file. An attacker with Orion alert management rights could use this vulnerability to perform an unrestricted file upload causing a remote code execution.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: SolarWinds

Published: 2021-12-20T20:08:24.786551Z

Updated: 2024-09-16T22:10:26.291Z

Reserved: 2021-06-22T00:00:00

Link: CVE-2021-35244

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-12-20T21:15:08.110

Modified: 2022-03-17T17:54:31.847

Link: CVE-2021-35244

cve-icon Redhat

No data.