OrbiTeam BSCW Classic before 7.4.3 allows authenticated remote code execution (RCE) during archive extraction via attacker-supplied Python code in the class attribute of a .bscw file. This is fixed in 5.0.12, 5.1.10, 5.2.4, 7.3.3, and 7.4.3.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T02:06:42.396Z

Reserved: 2021-08-18T00:00:00

Link: CVE-2021-39271

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-08-30T05:15:07.307

Modified: 2024-11-21T06:19:05.100

Link: CVE-2021-39271

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.