9.8

CVE-2021-28428

File upload vulnerability in HorizontCMS before 1.0.0-beta.3 via uploading a .htaccess and *.hello files using the Media Files upload functionality. The original file upload vulnerability (CVE-2020-27387) was remediated by restricting the PHP extensions; however, we confirmed that the filter was bypassed via uploading an arbitrary .htaccess and *.hello files in order to execute PHP code to gain RCE.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Horizontcms ProjectHorizontcms Version1.0.0 Update-
Horizontcms ProjectHorizontcms Version1.0.0 Updatealpha
Horizontcms ProjectHorizontcms Version1.0.0 Updatealpha2
Horizontcms ProjectHorizontcms Version1.0.0 Updatealpha3
Horizontcms ProjectHorizontcms Version1.0.0 Updatealpha4
Horizontcms ProjectHorizontcms Version1.0.0 Updatealpha5
Horizontcms ProjectHorizontcms Version1.0.0 Updatealpha6
Horizontcms ProjectHorizontcms Version1.0.0 Updatealpha7
Horizontcms ProjectHorizontcms Version1.0.0 Updatealpha8
Horizontcms ProjectHorizontcms Version1.0.0 Updatebeta
Horizontcms ProjectHorizontcms Version1.0.0 Updatebeta2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.43% 0.62
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.