Sploitus

CVE-2021-42342

4 known exploits for CVE-2021-42342

An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passed to CGI scripts without being prefixed with the CGI prefix. This permits tunneling untrusted environment variables into vulnerable CGI scripts.

Affected products
Goahead
Embedthis Goahead
≤ 4.1.3, 5.1.5
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
59.5% (99th percentile)
Weakness
CWE-434
NVD status
Modified
Published
2021-10-14
CVE-2021-42342 at NVD
Authoritative description, scoring and affected products

4 known exploits for CVE-2021-42342

Proof-of-concept code and exploit modules indexed by Sploitus