{ "id": "CVE-2021-27197", "sourceIdentifier": "cve@mitre.org", "published": "2021-02-12T16:15:12.627", "lastModified": "2021-02-19T19:33:21.777", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "DSUtility.dll in Pelco Digital Sentry Server before 7.19.67 has an arbitrary file write vulnerability. The AppendToTextFile method doesn't check if it's being called from the application or from a malicious user. The vulnerability is triggered when a remote attacker crafts an HTML page (e.g., with \"OBJECT classid=\" and \"