EXPOSURES › CVE-2021-36581
CVE-2021-36581
CRITICAL
DETAIL
SourceNVD · cve
Published2021-09-14
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-36581 ↗
⚡ RCE
SHAME 50/100
rce
Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The server does not verify the extension of the file and the tester was able to upload an aspx to the server.
▸ RECOMMENDED ACTION Remote code execution — patch the affected products on priority.
PLAYERS IMPLICATED
DESCRIPTION
Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The server does not verify the extension of the file and the tester was able to upload an aspx to the server.
SENTIMENT · TRUSTED SOURCES
synthesis
severe-fallout
-0.80
Widely condemned due to critical file upload vulnerability allowing ASPX execution
Damning
"Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The server does not verify the extension of the file and the tester was able to upload an aspx to the server."
Negative
Neutral
Negative
Negative
Neutral
Neutral
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.