Skip to content
COOEY

EXPOSURES › CVE-2021-36581

CVE-2021-36581

CRITICAL
DETAIL
SourceNVD · cve Published2021-09-14 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-36581 ↗
⚡ RCE SHAME 50/100 rce

Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The server does not verify the extension of the file and the tester was able to upload an aspx to the server.

▸ RECOMMENDED ACTION  Remote code execution — patch the affected products on priority.

DESCRIPTION

Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The server does not verify the extension of the file and the tester was able to upload an aspx to the server.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.80
Widely condemned due to critical file upload vulnerability allowing ASPX execution
cooey ↗ severe-fallout -0.90
Damning
"Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The server does not verify the extension of the file and the tester was able to upload an aspx to the server."
cvefeed.io ↗ severe-fallout -0.60
Negative
www.cvefind.com ↗ severe-fallout -0.50
Neutral
NVD ↗ severe-fallout -0.40
Negative
SentinelOne ↗ severe-fallout -0.30
Negative
www.pcworld.com ↗ severe-fallout +0.00
Neutral
www.cbc.ca ↗ severe-fallout +0.00
Neutral
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.