Vulnerability Description
Attackers can access the CGE account management function without privilege for permission elevation and execute arbitrary commands or files after obtaining user permissions.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Changjia Property Management System Project | Changjia Property Management System | 1.00 |
Related Weaknesses (CWE)
References
- https://www.chtsecurity.com/news/fe1e30ef-4dac-4848-a3c9-a7df12672422Third Party Advisory
- https://www.twcert.org.tw/tw/cp-132-4396-e6d44-1.htmlThird Party Advisory
- https://www.chtsecurity.com/news/fe1e30ef-4dac-4848-a3c9-a7df12672422Third Party Advisory
- https://www.twcert.org.tw/tw/cp-132-4396-e6d44-1.htmlThird Party Advisory
FAQ
What is CVE-2021-22858?
CVE-2021-22858 is a vulnerability with a CVSS score of 8.8 (HIGH). Attackers can access the CGE account management function without privilege for permission elevation and execute arbitrary commands or files after obtaining user permissions.
How severe is CVE-2021-22858?
CVE-2021-22858 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-22858?
Check the references section above for vendor advisories and patch information. Affected products include: Changjia Property Management System Project Changjia Property Management System.