Vulnerability Description
An issue was discovered in SmartFoxServer 2.17.0. An attacker can execute arbitrary Python code, and bypass the javashell.py protection mechanism, by creating /config/ConsoleModuleUnlock.txt and editing /config/admin/admintool.xml to enable the Console module.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Smartfoxserver | Smartfoxserver | 2.17.0 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/161340/SmartFoxServer-2X-2.17.0-Remote-CodeExploitThird Party AdvisoryVDB Entry
- https://www.smartfoxserver.comProduct
- https://www.zeroscience.mk/en/vulnerabilities/ExploitThird Party Advisory
- http://packetstormsecurity.com/files/161340/SmartFoxServer-2X-2.17.0-Remote-CodeExploitThird Party AdvisoryVDB Entry
- https://www.smartfoxserver.comProduct
- https://www.zeroscience.mk/en/vulnerabilities/ExploitThird Party Advisory
FAQ
What is CVE-2021-26551?
CVE-2021-26551 is a vulnerability with a CVSS score of 8.8 (HIGH). An issue was discovered in SmartFoxServer 2.17.0. An attacker can execute arbitrary Python code, and bypass the javashell.py protection mechanism, by creating /config/ConsoleModuleUnlock.txt and editi...
How severe is CVE-2021-26551?
CVE-2021-26551 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-26551?
Check the references section above for vendor advisories and patch information. Affected products include: Smartfoxserver Smartfoxserver.