KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary executable pathnames.
View the template here CVE-2021-36356.yaml
References:
https://github.com/ARPSyndicate/cvemon