Vulnerability Description
Machform prior to version 16 is vulnerable to unauthenticated remote code execution due to insufficient sanitization of file attachments uploaded with forms through upload.php.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Machform | Machform | < 16 |
Related Weaknesses (CWE)
References
- https://www.tenable.com/security/research/tra-2021-25%2Chttps://www.machform.com
- https://www.tenable.com/security/research/tra-2021-25%2Chttps://www.machform.com
FAQ
What is CVE-2021-20104?
CVE-2021-20104 is a vulnerability with a CVSS score of 8.1 (HIGH). Machform prior to version 16 is vulnerable to unauthenticated remote code execution due to insufficient sanitization of file attachments uploaded with forms through upload.php.
How severe is CVE-2021-20104?
CVE-2021-20104 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-20104?
Check the references section above for vendor advisories and patch information. Affected products include: Machform Machform.