cve/2021/CVE-2021-36202.md
2025-09-29 21:09:30 +02:00

967 B

CVE-2021-36202

Description

Server-Side Request Forgery (SSRF) vulnerability in Johnson Controls Metasys could allow an authenticated attacker to inject malicious code into the MUI PDF export feature. This issue affects: Johnson Controls Metasys All 10 versions versions prior to 10.1.5; All 11 versions versions prior to 11.0.2.

POC

Reference

Github

No PoCs found on GitHub currently.