CVE-2021-45834
Critical · CVSS 9.8OpenDocMan — Unrestricted File Upload via MIME-type bypass (CWE-434)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-434
Description
An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypass, which may be automatically processed within the product's environment or lead to arbitrary code execution.
Search profile — drives PoC discovery
Symbols add.phpMIME-bypassfile uploaddangerous file typesopendocman
Keywords CVE-2021-45834OpenDocMan1.4.4unrestricted file uploadMIME bypassadd.phparbitrary code executionPoCexploit
Versions: 1.4.4
References
- https://github.com/opendocman/opendocman
- https://github.com/opendocman/opendocman/issues/326
- https://github.com/opendocman/opendocman/issues/330
- http://opendocman.com
- https://github.com/opendocman/opendocman
- https://github.com/opendocman/opendocman/issues/326
- https://github.com/opendocman/opendocman/issues/330
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T06:30:39.000Z