Aller au contenu

Fiche vulnérabilité

CVE-2021-36581 : faille critique kooboo kooboo cms (CVSS 9.8)

Description

Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The server does not verify the extension of the file and the tester was able to upload an aspx to the server.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
14 sept. 2021
Dernière mise à jour
9 juil. 2026

Produits concernés

  • kooboo kooboo cms

Références

Rechercher une autre vulnérabilité dans la base CVE