CVE-2021-42342
An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passed to CGI scripts without being prefixed with the CGI prefix. This permits tunneling untrusted environment variables into vulnerable CGI scripts.
- Affected products
- Goahead
- Embedthis Goahead
- ≤ 4.1.3, 5.1.5
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 59.5% (99th percentile)
- Weakness
- CWE-434
- NVD status
- Modified
- Published
- 2021-10-14
CVE-2021-42342 at NVD
4 known exploits for CVE-2021-42342
Proof-of-concept code and exploit modules indexed by Sploitus