CVE-2021-47667 | ZendTo up to 6.10-6 lib/NSSDropoff.php tmp_name os command injection
A vulnerability was found in ZendTo up to 6.10-6. It has been classified as very critical. This affects an unknown part in the library lib/NSSDropoff.php. The manipulation of the argument tmp_name leads to os command injection.
This vulnerability is uniquely identified as CVE-2021-47667. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.