High severity7.4NVD Advisory· Published Dec 14, 2021· Updated Jun 17, 2026
CVE-2021-43829
CVE-2021-43829
Description
PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.7.7 PatrowlManager unrestrictly handle upload files in the findings import feature. This vulnerability is capable of uploading dangerous type of file to server leading to XSS attacks and potentially other forms of code injection. Users are advised to update to 1.7.7 as soon as possible. There are no known workarounds for this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<1.7.7+ 1 more
- (no CPE)range: <1.7.7
- (no CPE)range: < 1.7.7
Patches
Vulnerability mechanics
References
3- github.com/Patrowl/PatrowlManager/commit/2287c9715d2e7ef11b44bb0ad4a57727654f2203nvdPatchThird Party Advisory
- huntr.dev/bounties/17324785-f83a-4058-ac40-03f2bfa16399/nvdExploitPatchThird Party Advisory
- github.com/Patrowl/PatrowlManager/security/advisories/GHSA-5hc9-6hq4-2xfxnvdThird Party Advisory
News mentions
0No linked articles in our index yet.