CVE-2021-39608
Remote Code Execution (RCE) vulnerabilty exists in FlatCore-CMS 2.0.7 via the upload addon plugin, which could let a remote malicious user exeuct arbitrary php code.
- Affected products
- Flatcore-Cms
- Flatcore Flatcore-cms
- = 2.0.7
- Fix
- Available
- CVSS 2.0
- 9.0 HIGH
- CVSS 3.1
- 7.2 HIGH
- EPSS
- 45.9% (99th percentile)
- Weakness
- CWE-434
- NVD status
- Modified
- Published
- 2021-08-23
CVE-2021-39608 at NVD
3 known exploits for CVE-2021-39608
Proof-of-concept code and exploit modules indexed by Sploitus