{"id":"CVE-2021-40612","details":"An issue was discovered in Opmantek Open-AudIT after 3.5.0. Without authentication, a vulnerability in code_igniter/application/controllers/util.php allows an attacker perform command execution without echoes.","modified":"2026-03-15T14:44:46.507884Z","published":"2021-12-22T13:15:07.507Z","references":[{"type":"FIX","url":"https://community.opmantek.com/pages/viewpage.action?pageId=65504438"},{"type":"FIX","url":"https://github.com/Opmantek/open-audit/commit/c7595cbb092e410a487f03c0eb536cf19e538860"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/opmantek/open-audit","events":[{"introduced":"e35466b0b32e12a6a3488f67c19cd162339473de"},{"fixed":"adaf2a44746b2b2ed9a9c3bf10ffb920c9c2d0b5"},{"fixed":"c7595cbb092e410a487f03c0eb536cf19e538860"}],"database_specific":{"versions":[{"introduced":"3.5.0"},{"fixed":"4.3.0"}]}}],"versions":["Open-AudIT_3.5.0","Open-AudIT_3.5.1","Open-AudIT_3.5.2","Open-AudIT_4.1.1","Open-AudIT_4.1.2","Open-AudIT_4.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-40612.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}