CVE-2021-47794

ZesleCP 3.1.9 contains an authenticated remote code execution vulnerability that allows attackers to create malicious FTP accounts with shell injection payloads. Attackers can exploit the FTP account creation endpoint by injecting a reverse shell command that establishes a network connection to a specified listening host.
Configurations

Configuration 1 (hide)

cpe:2.3:a:zesle:zeslecp:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-16 00:16

Updated : 2026-01-21 21:56


NVD link : CVE-2021-47794

Mitre link : CVE-2021-47794

CVE.ORG link : CVE-2021-47794


JSON object : View

Products Affected

zesle

  • zeslecp
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')