Back to Database
Status published
Critical
CVE-2021-29281
File upload vulnerability in GFI Mail Archiver versions up to...
Vulnerability Description
File upload vulnerability in GFI Mail Archiver versions up to and including 15.1 via insecure implementation of Telerik Web UI plugin which is affected by CVE-2014-2217, and CVE-2017-11317.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-29281
Credits & Attribution
No credits recorded in the NVD database.
References
- https://cwe.mitre.org/data/definitions/434.html
- https://owasp.org/www-community/vulnerabilities/Unrestricted_File_Upload
- https://www.gfi.com/products-and-solutions/network-security-solutions/gfi-archiver
- https://aminbohio.com/gfi-mail-archiver-15-1-telerik-ui-component-arbitrary-file-upload-unauthenticated-exploit/
- https://www.exploit-db.com/exploits/50181
More from gfi
View All →CVE-2019-16414
A DOM based XSS in GFI Kerio Control v9.3.0 allows...
Medium
6.1
CVE-2017-7440
Kerio Connect 8.0.0 through 9.2.2, and Kerio Connect Client desktop...
Medium
6.5
CVE-2010-5254
Untrusted search path vulnerability in GFI Backup 3.1 Build 20100730...
Medium
6.9
CVE-2010-5181
Race condition in VIPRE Antivirus Premium 4.0.3272 on Windows XP...
Unknown
0
CVE-2005-3182
Buffer overflow in the HTTP management interface for GFI MailSecurity...
High
7.5
Affected Vendor
Affected Software
archiver
Vulnerable Versions:
0
Timeline
Official Publish:
July 7th, 2022
Last Modified:
August 3rd, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.