Back

CRITICAL

Unrestricted upload of dangerous file types in C21 Live Encoder and Live Mosaic

Published Jan 17, 2024

Description

Unrestricted upload of dangerous file types in the C21 Live Encoder and Live Mosaic product, version 5.3. This vulnerability allows a remote attacker to upload different file extensions without any restrictions, resulting in a full system compromise.

Affected products

Remediation

Vendor solution

The vulnerability has been resolved by the Cires21 team in the latest software version of the affected products, which was released in the last week of November.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCIBE
Published Jan 17, 2024
Updated Jun 2, 2025
Reserved Jan 17, 2024
CISA Vulnrichment
Updated May 8, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a