CVE-2021-21978
VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of authorization leading to arbitrary file upload in logupload web application. An unauthorized attacker with network access to View Planner Harness could upload and execute a specially crafted file leading to remote code execution within the logupload container.
- Affected products
- Vmware View Planner
- Vmware View Planner
- < 4.6
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 99.0% (100th percentile)
- Weakness
- CWE-20, CWE-862
- NVD status
- Modified
- Published
- 2021-03-03
CVE-2021-21978 at NVD
11 known exploits for CVE-2021-21978
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2021-21978
CVE-2021-21978
CVE-2021-21978
VMware View Planner 4.6 Remote Code Execution
VMware View Planner 4.6 Remote Code Execution Exploit
Exploit for Server-Side Request Forgery in Microsoft
Exploit for Server-Side Request Forgery in Microsoft
Exploit for Improper Input Validation in Vmware View_Planner
Exploit for Improper Input Validation in Vmware View_Planner
Exploit for Improper Input Validation in Vmware View_Planner
VMware View Planner Unauthenticated Log File Upload RCE