FAIL › dossier
kooboo cms
PRODUCT· dossier confidence 0%
Kooboo CMS is a content management system with a critical security track record. The vendor failed to patch severe remote code execution vulnerabilities in its file upload functionality, allowing attackers to execute arbitrary code via uploaded files.
PROFILE
CategoryCMSWhat they doKooboo CMS is a content management system.
SECURITY POSTURE
The vendor has a critical track record of unpatched vulnerabilities in its core file upload functionality, allowing remote code execution via arbitrary file extensions.
Notable failures
- CVE-2021-36581: Insecure file upload allowing arbitrary extensions
- CVE-2021-36582: Remote shell upload leading to reverse shell
Patterns: repeated unpatched edge-device RCEs; insecure file upload handling
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2021-09-14 | CVE-2021-36581 | critical | Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The server does not verify the extension of the file and the tester was able to upload an aspx to the server. |
| 2021-09-14 | CVE-2021-36582 | critical | In Kooboo CMS 2.1.1.0, it is possible to upload a remote shell (e.g., aspx) to the server and then call upon it to receive a reverse shell from the victim server. The files are uploaded to /Content/Template/root/reverse-shell.aspx and can be simply triggered by browsing that URL. |
DOSSIER SOURCES
- Business Entity Search | Secretary of State Lookup · entitysearch.us
- CMS Reprimands AI Vendor Over WISeR Prior Authorization Delays · distilinfo.com
- Parent Company and Subsidiary Verification Using KYB and Corporate ... · facia.io
Open questions: Kooboo CMS vendor identity and corporate structure · Post-CVE-2021 patching timeline and remediation efforts
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-21 04:00:53.862311+00:00