← Vulnerability feed

Vulnerability record · CVE-2021-43829 · published 14 December 2021

CVE-2021-43829: PatrOwl PatrowlManager unrestricted file upload in findings import

Patrowl · Patrowlmanager

PatrowlManager before 1.7.7 does not restrict file types in the findings import feature, allowing upload of dangerous files. This enables cross-site scripting and potentially other code injection on the server. The flaw is remotely reachable and rated high severity (CVSS 8.8).

8.8 CVSS 3.1 High EPSS 59% · top 0.9% CWE-434 · Unrestricted file upload
8.8CVSS 3.1 base score, v2 6.5
59%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.7.7 PatrowlManager unrestrictly handle upload files in the findings import feature. This vulnerability is capable of uploading dangerous type of file to server leading to XSS attacks and potentially other forms of code injection. Users are advised to update to 1.7.7 as soon as possible. There are no known workarounds for this issue.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityCVSS 8.8 with a public exploit reference and very high EPSS percentile, though no KEV listing and exploitation requires authentication.

What it is

PatrowlManager before 1.7.7 does not restrict file types in the findings import feature, allowing upload of dangerous files. This enables cross-site scripting and potentially other code injection on the server. The flaw is remotely reachable and rated high severity (CVSS 8.8).

Impact

An authenticated attacker can upload malicious files that execute script in other users' browsers or inject code on the server, compromising confidentiality, integrity and availability.

Attack surface

Reached over the network through the findings import upload feature; the CVSS vector requires low privileges (PR:L) and no user interaction (UI:N).

Exploitation

Not listed in CISA KEV, but EPSS is high (0.59, 99th percentile) and a public exploit reference exists on huntr.dev, indicating meaningful exploitation likelihood.

What to do

  • Upgrade PatrowlManager to version 1.7.7 or later, which contains the patch commit.
  • Restrict the findings import feature to trusted users and enforce strict file type and content validation.
  • Store uploaded files outside the web root and serve them with a non-executable content type.
  • Apply a web application firewall rule to block executable or script file uploads to the import endpoint.

Detection

  • Monitor upload requests to the findings import endpoint for executable, script or HTML file extensions.
  • Alert on files written to web-accessible directories with script or executable content.
  • Review server logs for anomalous POST requests to import functionality from low-privilege accounts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-43829 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2021-43828Patrowlmanager improper privilege management vulnerabilityPatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.77 an improper privilege management (IDOR) h…EPSS 1.4%10.0CVE-2026-56291Balbooa Forms Joomla extension unauthenticated arbitrary file upload RCEThe Balbooa Forms extension for Joomla before version 2.4.1 accepts file uploads without authentication and does not restrict file type, allowing exe…KEVEPSS 15%analysed10.0CVE-2026-48939iCagenda Joomla extension unrestricted file upload leads to PHP RCEThe iCagenda extension for Joomla fails to restrict file types in its file attachment feature, allowing arbitrary file uploads that result in PHP cod…KEVEPSS 20%analysed10.0CVE-2026-56290Joomla Page Builder CK unauthenticated file upload leads to RCEThe Joomla Page Builder CK extension before 3.6.0 allows unauthenticated arbitrary file uploads, letting an attacker place executable files on the se…KEVEPSS 31%analysed10.0CVE-2026-48908SP Page Builder for Joomla unauthenticated arbitrary file upload RCESP Page Builder for Joomla permits unauthenticated users to upload arbitrary files, which can lead to upload and execution of PHP code. The flaw is a…KEVEPSS 89%analysed9.8CVE-2024-7399Samsung MagicINFO 9 Server path traversal allows arbitrary file writeSamsung MagicINFO 9 Server before version 21.1050 contains a path traversal flaw (CWE-22) that also enables unrestricted file upload (CWE-434), letti…KEVEPSS 92%analysed7.2CVE-2025-2749Kentico Xperience path traversal and file upload lead to RCEKentico Xperience through 13.0.178 allows an authenticated Staging Sync Server user to upload arbitrary data to relative paths, enabling path travers…KEVEPSS 4.1%analysed7.2CVE-2024-7694ThreatSonar Anti-Ransomware unrestricted file upload enables command executionThreatSonar Anti-Ransomware from TeamT5 fails to properly validate the content of uploaded files (CWE-434). An attacker holding administrator privile…KEVEPSS 1.8%analysed

Source: NIST National Vulnerability Database (record CVE-2021-43829), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.