Vulnerability record · CVE-2021-45834 · published 18 March 2022
CVE-2021-45834: Opendocman unrestricted file upload vulnerability
Opendocman · Opendocman
An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypass, which may be automatically processed within the product's environment or lead to arbitrary code execution.
Description
An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypass, which may be automatically processed within the product's environment or lead to arbitrary code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/opendocman/opendocman | ProductThird Party Advisory |
| https://github.com/opendocman/opendocman/issues/326 | Issue TrackingThird Party Advisory |
| https://github.com/opendocman/opendocman/issues/330 | ExploitIssue TrackingThird Party Advisory |
| https://github.com/opendocman/opendocman | ProductThird Party Advisory |
| https://github.com/opendocman/opendocman/issues/326 | Issue TrackingThird Party Advisory |
| https://github.com/opendocman/opendocman/issues/330 | ExploitIssue TrackingThird Party Advisory |
Track CVE-2021-45834 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-45834), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.