### [CVE-2017-20021](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-20021) ![](https://img.shields.io/static/v1?label=Product&message=Solar-Log&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=2.8.4-56%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Version&message=3.5.2-85%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-269%20Improper%20Privilege%20Management&color=brightgreen) ### Description A vulnerability, which was classified as critical, was found in Solare Solar-Log 2.8.4-56/3.5.2-85. This affects an unknown part of the component File Upload. The manipulation leads to privilege escalation. It is possible to initiate the attack remotely. Upgrading to version 3.5.3-86 is able to address this issue. It is recommended to upgrade the affected component. ### POC #### Reference - http://seclists.org/fulldisclosure/2017/Mar/58 #### Github No PoCs found on GitHub currently.