CVE-2021-42171
Unrestricted Upload of File with Dangerous Type in Zenario CMS
9.8
CRITICAL
CVSS 3.1
EPSS 17.8%
Description
Zenario CMS 9.0.54156 is vulnerable to File Upload. The web server can be compromised by uploading and executing a web-shell which can run commands, browse system files, browse local resources, attack other servers, and exploit the local vulnerabilities, and so forth.
How to fix CVE-2021-42171
To remediate CVE-2021-42171, upgrade the affected package to a fixed version below.
- —upgrade to 9.0.55143 or later
Is CVE-2021-42171 being exploited?
Moderate — EPSS is 17.8%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 9.0.55143
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |